Skills mcp-builder
๐Ÿ“ฆ

mcp-builder

Content revision r1 Medium Risk ๐Ÿ”‘ Env variablesโš™๏ธ External commands๐ŸŒ Network access

Build MCP Servers with mcp-use

MCP developers need consistent patterns for tools, resources, prompts, and widgets. This skill summarizes mcp-use implementation patterns and warns that new work should use mcp-app-builder.

Supports: Claude Codex Code(CC)
๐Ÿ“Š 67 Adequate

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "mcp-builder" from https://skillstore.io/skills/shubhamsaboo-mcp-builder.md and its manifest at https://skillstore.io/api/skills/shubhamsaboo-mcp-builder/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "mcp-builder". Build a weather tool with a widget.

Expected outcome:

A short implementation plan with the tool schema, widget name, response helper, and environment variable setup.

Using "mcp-builder". Add a user profile resource.

Expected outcome:

A resource design with a parameterized URI, user identifier validation, structured profile data, and not-found handling.

Using "mcp-builder". Create a code review prompt.

Expected outcome:

A prompt template specification with described fields, completion guidance, and response helper selection.

Security Audit

Medium Risk
v2 โ€ข 7/7/2026 Open versioned report

Most static findings are false positives from Markdown code fences, TypeScript template literals, environment variable examples, and localhost URLs. One real issue remains: the deprecated skill asks users to run an npx installer for a replacement skill. No prompt injection text or credential exfiltration intent was found.

12
Files scanned
1,805
Lines analyzed
1
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Deprecated Skill Redirects Users to External Installer
The skill description tells users to run an npx installer for mcp-app-builder. This can trigger package-manager execution from a community entry.
The deprecation block directly names an npx install command and tells users to use another skill. Execution still requires user or agent action.
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Medium
Ruby/shell backtick execution
`npx skills install mcp-use/mcp-use --skill mcp-app-builder`
The skill description instructs users to run an npx installer for a replacement skill. That creates package-manager supply-chain risk in a community skill.

Risk Factors

๐Ÿ”‘ Env variables (18)
โš™๏ธ External commands (37)
๐ŸŒ Network access (6)
Audited by: codex View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/shubhamsaboo-mcp-builder/audits/2?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/shubhamsaboo-mcp-builder/security.svg)](https://skillstore.io/skills/shubhamsaboo-mcp-builder?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/shubhamsaboo-mcp-builder?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/shubhamsaboo-mcp-builder/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/shubhamsaboo-mcp-builder.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

shubhamsaboo. (2026). mcp-builder security audit report (audit version 2) [Author version unspecified]. Skillstore. https://skillstore.io/skills/shubhamsaboo-mcp-builder/audits/2

BibTeX citation

@techreport{shubhamsaboo-shubhamsaboo-mcp-builder-2026, author = {shubhamsaboo}, title = {mcp-builder security audit report (audit version 2)}, institution = {Skillstore}, year = {2026}, number = {2}, url = {https://skillstore.io/skills/shubhamsaboo-mcp-builder/audits/2}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "mcp-builder security audit report (audit version 2)" version: "unspecified" type: report authors: - name: "shubhamsaboo" date-released: "2026-07-07" url: "https://skillstore.io/skills/shubhamsaboo-mcp-builder/audits/2" identifiers: - type: other value: "skillstore:shubhamsaboo-mcp-builder:audit:2" description: "Skillstore immutable audit report identifier"

Compare variants

15 installable variants

Each author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.

Why this variant is first

Highest Skillstore Score
Doyajin174 Recommended

doyajin174-mcp-builder

Skillstore Score 78
Evidence Confidence High
Skillstore usage 13
Updated

2026-08-21

mcp-builder

Skillstore Score 75
Evidence Confidence High
Skillstore usage 15
Updated

2026-08-21

azeem-2-mcp-builder

Skillstore Score 75
Evidence Confidence High
Skillstore usage 8
Updated

2026-08-21

mcp-use-mcp-builder

Skillstore Score 68
Evidence Confidence High
Skillstore usage 10
Updated

2026-08-21

shubhamsaboo Current

shubhamsaboo-mcp-builder

Skillstore Score 67
Evidence Confidence Medium
Skillstore usage 5
Updated

2026-08-21

yyh211-mcp-builder

Skillstore Score 66
Evidence Confidence High
Skillstore usage 68
Updated

2026-08-21

cam10001110101-mcp-builder

Skillstore Score 66
Evidence Confidence High
Skillstore usage 10
Updated

2026-08-21

dyai2025-mcp-builder

Skillstore Score 66
Evidence Confidence High
Skillstore usage 7
Updated

2026-08-21

zhanlincui-mcp-builder

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 22
Updated

2026-08-21

92bilal26-mcp-builder

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 17
Updated

2026-08-21

sickn33-mcp-builder

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 13
Updated

2026-08-21

artemisai-mcp-builder

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 10
Updated

2026-08-21

composiohq-mcp-builder

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 9
Updated

2026-08-21

autumnsgrove-mcp-builder

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 9
Updated

2026-08-21

davila7-mcp-builder

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 7
Updated

2026-08-21

Skillstore Score

Why this score Evidence Confidence: Medium
45
Architecture
85
Maintainability
87
Content
65
Community
91
Spec Compliance

What You Can Build

Create MCP Tools

Design tool schemas, response helpers, and error handling for mcp-use servers.

Model Read-Only Data

Define resources and resource templates for configuration, profiles, and other structured data.

Add Interactive Widgets

Connect server-side MCP tools to React TSX widget files and visible tool output.

Try These Prompts

Create a Basic Tool
Create a basic mcp-use tool for this task: [task]. Include schema fields, descriptions, response helper choice, and error handling.
Add Resources and Prompts
Design MCP resources and prompts for this server: [server goal]. Separate read-only data from actions and explain each URI pattern.
Build a Widget Workflow
Plan a widget-backed MCP workflow for [user workflow]. Include tool names, widget props, model-visible output, and loading states.
Review Production Readiness
Review this mcp-use server plan for production readiness. Check schemas, destructive actions, environment variables, widgets, and deployment assumptions.

Best Practices

  • Prefer mcp-app-builder for new work because this skill is deprecated.
  • Require explicit approval before running package-manager install commands.
  • Document required environment variables with empty examples, not real credentials.

Avoid

  • Do not paste real API keys into examples or generated files.
  • Do not treat destructive actions as read-only MCP tools.
  • Do not expose widget props to the model when private data is only for UI.

Frequently Asked Questions

Is this skill current?
No. It is deprecated and directs new users to mcp-app-builder.
What framework does it target?
It targets MCP servers built with the mcp-use framework.
Can it help build widgets?
Yes. It explains React TSX widgets, widget metadata, tool output, and the useWidget hook.
Does it run commands automatically?
No. It contains an npx install instruction that should require human approval before use.
Which AI tools can use it?
It lists support for Claude, Codex, and Claude Code.
How should secrets be handled?
Use environment variables and .env.example files with empty values. Never store real secrets in generated projects.

Developer Details

License

MIT

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

412e23e39ccd9729546286287b96bb41707397cf

Maintenance freshness

7/18/2026

Usage

2 downloads ยท 0 views

File structure

๐Ÿ“ evals/

๐Ÿ“„ architecture.json

๐Ÿ“„ implementation.json

๐Ÿ“„ README.md

๐Ÿ“„ skill.json

๐Ÿ“„ widgets.json

๐Ÿ“ references/

๐Ÿ“„ design-and-architecture.md

๐Ÿ“„ resource-templates.md

๐Ÿ“„ response-helpers.md

๐Ÿ“„ tools-and-resources.md

๐Ÿ“„ widgets.md

๐Ÿ“„ LICENSE.txt

๐Ÿ“„ SKILL.md