MCP Integration
Build MCP Integrations for Claude Code
MCP setup across transports, auth, and tool naming is easy to misconfigure. This skill guides Claude Code plugin authors through MCP server configuration and usage.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "MCP Integration" from https://skillstore.io/skills/davila7-mcp-integration.md and its manifest at https://skillstore.io/api/skills/davila7-mcp-integration/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "MCP Integration". I need to connect a plugin to an HTTP API with a bearer token.
Expected outcome:
- Recommended HTTP transport for stateless API calls.
- Use an environment variable for the bearer token.
- Document token scopes, setup steps, and common auth failures.
Using "MCP Integration". My command needs to create and search tasks through an MCP server.
Expected outcome:
- List only the specific MCP tools needed by the command.
- Validate required user inputs before each tool call.
- Return clear success, partial success, and failure messages.
Using "MCP Integration". I want to support both local development and production endpoints.
Expected outcome:
- Use environment variables for endpoint selection.
- Prefer secure production URLs and scoped tokens.
- Add troubleshooting steps for missing variables and failed connections.
Security Audit
High RiskMost static alerts are false positives caused by Markdown fences, placeholders, example URLs, and documented authentication patterns. The audit confirms unsafe `.env` loading guidance that can execute file contents. Additional risks include unpinned package execution, broad filesystem access, unrestricted autonomous tools, and secret-printing troubleshooting.
Confirmed security concerns (5)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
๐ Network access (37)
๐ Env variables (22)
โ๏ธ External commands (50)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/davila7-mcp-integration/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/davila7-mcp-integration?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/davila7-mcp-integration?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/davila7-mcp-integration/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/davila7-mcp-integration.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
davila7. (2026). MCP Integration security audit report (audit version 9) [Author version 0.1.0]. Skillstore. https://skillstore.io/skills/davila7-mcp-integration/audits/9BibTeX citation
@techreport{davila7-davila7-mcp-integration-2026,
author = {davila7},
title = {MCP Integration security audit report (audit version 9)},
institution = {Skillstore},
year = {2026},
number = {9},
url = {https://skillstore.io/skills/davila7-mcp-integration/audits/9},
note = {Author version 0.1.0}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "MCP Integration security audit report (audit version 9)"
version: "0.1.0"
type: report
authors:
- name: "davila7"
date-released: "2026-07-19"
url: "https://skillstore.io/skills/davila7-mcp-integration/audits/9"
identifiers:
- type: other
value: "skillstore:davila7-mcp-integration:audit:9"
description: "Skillstore immutable audit report identifier"
Compare variants
4 installable variantsEach author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.
Why this variant is first
mcp-integration
2026-09-09
89jobrien-mcp-integration
2026-09-09
anthropics-mcp-integration
2026-09-09
davila7-mcp-integration
2026-09-09
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Add a Hosted MCP Server
Configure an SSE or HTTP MCP endpoint with clear auth and setup notes.
Review Local Server Configuration
Check stdio server commands, environment variables, and portable plugin paths.
Document MCP Tool Workflows
Map MCP tool names into commands, agents, and troubleshooting guidance.
Try These Prompts
Help me add a basic MCP server to my Claude Code plugin. Ask which transport I need, then outline the configuration.
Compare stdio, SSE, HTTP, and WebSocket for my plugin. Recommend one based on local execution, auth, latency, and setup needs.
Design an authentication plan for my MCP integration. Cover OAuth, environment variables, token scopes, and user setup documentation.
Review my planned multi-server MCP plugin architecture. Check server types, allowed tools, auth boundaries, error handling, and troubleshooting coverage.
Best Practices
- Use HTTPS or WSS for hosted MCP servers.
- Pre-allow only the MCP tools each command actually needs.
- Document every required environment variable and permission scope.
Avoid
- Do not hardcode tokens, API keys, or database credentials.
- Do not use wildcard MCP tool access unless the workflow requires it.
- Do not copy example URLs or placeholders into production unchanged.
Frequently Asked Questions
What does this skill help me build?
Does it create MCP server code?
Which MCP transports are covered?
How should secrets be handled?
Can it help with Claude Code command permissions?
Is this only useful for Claude Code?
Developer Details
Author
davila7License
MIT
Author version
v0.1.0
Skillstore revision
r1
Ref
dbe0e719813583400773166a0621f8a9b8185c72
Maintenance freshness
7/20/2026
Usage
4 downloads ยท 549 views
File structure
๐ examples/
๐ http-server.json
๐ sse-server.json
๐ stdio-server.json
๐ references/
๐ authentication.md
๐ server-types.md
๐ tool-usage.md
๐ SKILL.md