create-mcp-skill
Create MCP Skill Templates
Building a skill around an MCP server requires reliable discovery, testing, and documentation. This skill gives Claude, Codex, and Claude Code a structured workflow for MCP skill creation.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "create-mcp-skill" from https://skillstore.io/skills/cygnusfear-create-mcp-skill.md and its manifest at https://skillstore.io/api/skills/cygnusfear-create-mcp-skill/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "create-mcp-skill". Create a skill for a browser automation MCP server.
Expected outcome:
- A skill folder plan with a clear SKILL.md outline.
- A list of discovered browser tools and safe test tasks.
- A quick start section with reviewed command patterns.
Using "create-mcp-skill". Improve an existing MCP skill draft.
Expected outcome:
- A revised structure for setup, quick starts, tool reference, and troubleshooting.
- Notes about unsafe commands, broad permissions, and missing package pinning.
- A checklist for testing examples before publication.
Using "create-mcp-skill". Prepare documentation after MCP tool discovery.
Expected outcome:
- Plain-language tool descriptions with parameter notes.
- Warnings for optional parameters, timeouts, and server-specific quirks.
- Practical next steps for completing the skill file.
Security Audit
High RiskMost static findings are Markdown code fences, inline examples, or documentation links rather than literal Ruby backtick execution, path traversal, or hardcoded network callbacks. Context review still found high-risk guidance: the skill encourages execution of user-supplied MCP server commands, unpinned package runners, and a broad filesystem server example. No prompt injection text was found in SKILL.md.
Confirmed security concerns (4)
Risk Factors
โ๏ธ External commands (52)
๐ Network access (3)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/cygnusfear-create-mcp-skill/audits/8?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/cygnusfear-create-mcp-skill?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/cygnusfear-create-mcp-skill?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/cygnusfear-create-mcp-skill/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/cygnusfear-create-mcp-skill.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
Cygnusfear. (2026). create-mcp-skill security audit report (audit version 8) [Author version unspecified]. Skillstore. https://skillstore.io/skills/cygnusfear-create-mcp-skill/audits/8BibTeX citation
@techreport{cygnusfear-cygnusfear-create-mcp-skill-2026,
author = {Cygnusfear},
title = {create-mcp-skill security audit report (audit version 8)},
institution = {Skillstore},
year = {2026},
number = {8},
url = {https://skillstore.io/skills/cygnusfear-create-mcp-skill/audits/8},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "create-mcp-skill security audit report (audit version 8)"
version: "unspecified"
type: report
authors:
- name: "Cygnusfear"
date-released: "2026-07-05"
url: "https://skillstore.io/skills/cygnusfear-create-mcp-skill/audits/8"
identifiers:
- type: other
value: "skillstore:cygnusfear-create-mcp-skill:audit:8"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Create a new MCP skill
Build a starter skill file after discovering a target MCP server and its tools.
Standardize MCP skill documentation
Apply a repeatable structure for setup, quick starts, tool notes, and troubleshooting.
Test MCP tool behavior
Exercise MCP tools with controlled inputs before adding examples to a published skill.
Try These Prompts
Create a new skill for my MCP server. Ask for the server command, discover available tools, and draft the initial SKILL.md.
Review the MCP tools I discovered. Summarize the useful tools, required parameters, optional parameters, and safe example tasks.
Rewrite my MCP skill examples to use shell mode, timeouts, clean exits, and concise troubleshooting notes.
Review this MCP skill draft for least-privilege tools, unsafe package execution, broad filesystem access, and unclear cleanup commands.
Best Practices
- Pin third-party MCP package versions before copying command examples.
- Test each MCP tool with harmless inputs before documenting workflows.
- Keep generated skill permissions limited to the required tools.
Avoid
- Using latest package versions in production skill examples.
- Running user-supplied server commands without confirmation.
- Copying broad process-kill patterns into unrelated skills.
Frequently Asked Questions
Does this skill run MCP servers automatically?
What tools does it require?
Can it create a complete skill file?
Is it safe for untrusted MCP packages?
Does it support Claude Code and Codex?
Can I customize command examples?
Developer Details
Author
CygnusfearLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
7e9e368dc1a370f2040369ebcd0db06d90cb48e5
Maintenance freshness
7/18/2026
Usage
5 downloads ยท 302 views
File structure
๐ SKILL.md