All skills
jeffallan avatar

/mcp-developer

@efebc44
by jeffallanjeffallan/claude-skills12k stars
1,124

Use when building, debugging, or extending MCP servers or clients that connect AI systems with external tools and data sources. Invoke to implement tool handlers, configure resource providers, set up stdio/HTTP/SSE transport layers, validate schemas with Zod or Pydantic, debug protocol compliance issues, or scaffold complete MCP server/client projects using TypeScript or Python SDKs.

Use this Skill: https://skilld.dev/gh/jeffallan/claude-skills/mcp-developer

This session only. Nothing lands on disk.

referencesprotocol.md

≈1.3k tokens on demand. Your agent reads this file only when SKILL.md points to it.

MCP Protocol Specification

Protocol Overview

MCP is built on JSON-RPC 2.0 and enables bidirectional communication between clients (like Claude Desktop) and servers that provide resources, tools, and prompts.

Message Types

Request/Response

// Request format
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/list",
  "params": {}
}

// Success response
{
  "jsonrpc": "2.0",
  "id": 1,
  "result": {
    "tools": [
      {
        "name": "get_weather",
        "description": "Get weather for a location",
        "inputSchema": {
          "type": "object",
          "properties": {
            "location": { "type": "string" }
          },
          "required": ["location"]
        }
      }
    ]
  }
}

// Error response
{
  "jsonrpc": "2.0",
  "id": 1,
  "error": {
    "code": -32602,
    "message": "Invalid params",
    "data": { "details": "location is required" }
  }
}

Notifications

// Server sends notification (no response expected)
{
  "jsonrpc": "2.0",
  "method": "notifications/resources/updated",
  "params": {
    "uri": "file:///project/data.json"
  }
}

Connection Lifecycle

1. Client initiates connection (stdio/HTTP/SSE)
2. Client sends initialize request
   → Server responds with capabilities
3. Client sends initialized notification
4. Normal operation (requests/notifications)
5. Client/server can ping for keepalive
6. Client sends shutdown request
7. Connection closes

Initialize Handshake

// Client initialize request
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "initialize",
  "params": {
    "protocolVersion": "2024-11-05",
    "capabilities": {
      "roots": { "listChanged": true },
      "sampling": {}
    },
    "clientInfo": {
      "name": "claude-desktop",
      "version": "1.0.0"
    }
  }
}

// Server response
{
  "jsonrpc": "2.0",
  "id": 1,
  "result": {
    "protocolVersion": "2024-11-05",
    "capabilities": {
      "resources": { "subscribe": true, "listChanged": true },
      "tools": { "listChanged": true },
      "prompts": { "listChanged": true }
    },
    "serverInfo": {
      "name": "my-mcp-server",
      "version": "1.0.0"
    }
  }
}

// Client sends initialized notification
{
  "jsonrpc": "2.0",
  "method": "notifications/initialized"
}

Core Methods

Resources

// List available resources
resources/list → { resources: Resource[] }

// Read resource content
resources/read { uri: string } → { contents: ResourceContent[] }

// Subscribe to resource updates (if supported)
resources/subscribe { uri: string } → {}

// Unsubscribe
resources/unsubscribe { uri: string } → {}

// Server notifies of changes
notifications/resources/list_changed → {}
notifications/resources/updated { uri: string } → {}

Tools

// List available tools
tools/list → { tools: Tool[] }

// Execute tool
tools/call {
  name: string,
  arguments: object
} → { content: ToolResponse[] }

// Server notifies of tool changes
notifications/tools/list_changed → {}

Prompts

// List available prompts
prompts/list → { prompts: Prompt[] }

// Get prompt with arguments
prompts/get {
  name: string,
  arguments?: object
} → { messages: PromptMessage[] }

// Server notifies of prompt changes
notifications/prompts/list_changed → {}

Error Codes

Standard JSON-RPC 2.0 codes plus MCP-specific:

const ERROR_CODES = {
  // JSON-RPC 2.0 standard
  PARSE_ERROR: -32700,
  INVALID_REQUEST: -32600,
  METHOD_NOT_FOUND: -32601,
  INVALID_PARAMS: -32602,
  INTERNAL_ERROR: -32603,

  // MCP-specific (implementation defined)
  RESOURCE_NOT_FOUND: -32001,
  TOOL_EXECUTION_ERROR: -32002,
  UNAUTHORIZED: -32003,
  RATE_LIMIT_EXCEEDED: -32004
};

Transport Mechanisms

stdio (Standard Input/Output)

// Server reads from stdin, writes to stdout
// Each message is newline-delimited JSON
// Used for local integration (Claude Desktop default)

HTTP with SSE (Server-Sent Events)

// Client POSTs JSON-RPC requests to endpoint
// Server streams responses and notifications via SSE
// Used for remote servers

POST /mcp HTTP/1.1
Content-Type: application/json

{"jsonrpc":"2.0","id":1,"method":"tools/list"}

// SSE response
GET /mcp/sse HTTP/1.1

event: message
data: {"jsonrpc":"2.0","id":1,"result":{...}}

Protocol Versions

Current version: 2024-11-05

Servers must declare supported version in initialize response. Clients should verify compatibility.

Best Practices

  1. Validation: Always validate params with JSON Schema
  2. Error handling: Return structured errors with helpful messages
  3. Versioning: Check protocol version in initialize
  4. Timeouts: Implement request timeouts (30s recommended)
  5. Logging: Log all protocol messages for debugging
  6. Stateless: Design tools/resources to be stateless
  7. Idempotency: Make tool calls idempotent when possible
  8. Notifications: Use notifications for real-time updates

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    This skill acts as a comprehensive technical guide for developers building servers and clients using the Model Context Protocol (MCP). It provides implementation patterns for TypeScript and Python, including code for tool and resource handlers, protocol specifications, and security best practices. While automated scanners flagged the documentation URL and the skill file, manual review confirms these are likely false positives attributed to the technical code content and the author's own domain.

  • Socket16d

    1 alert: gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    3/6 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at efebc44. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 5 months ago
Other metadata
metadata
{
  "author": "https://github.com/Jeffallan",
  "version": "1.1.0",
  "domain": "api-architecture",
  "triggers": "MCP, Model Context Protocol, MCP server, MCP client, Claude integration, AI tools, context protocol, JSON-RPC",
  "role": "specialist",
  "scope": "implementation",
  "output-format": "code",
  "related-skills": "fastapi-expert, typescript-pro, security-reviewer, devops-engineer"
}

README badge

README badge for jeffallan/claude-skills/mcp-developer

Implements Model Context Protocol servers and clients that connect AI systems with external tools and data sources. Covers tool registration with Zod/Pydantic validation, resource providers, stdio/HTTP/SSE transports, protocol compliance testing via the MCP inspector, and scaffolding complete projects in TypeScript or Python.

Generated from the current SKILL.md.

Does this skill work with both TypeScript and Python?
Yes. The skill covers both the TypeScript SDK (Node.js) and Python SDK, with scaffolding and examples for each. Choose based on your project's language and runtime.
What transport mechanisms does this skill support?
The skill covers stdio, HTTP, and SSE transports. Stdio is the default for local Claude integration; HTTP and SSE are used for remote or web-based clients.
How do I validate tool inputs?
Use Zod schemas in TypeScript or Pydantic models in Python. The skill includes examples and references for defining validated input schemas for each tool.
How do I test an MCP server for protocol compliance?
Run `npx @modelcontextprotocol/inspector` to interactively verify that tools appear, schemas validate correctly, and responses are well-formed JSON-RPC 2.0. The skill includes a feedback loop for diagnosing and fixing schema or transport issues.
Does this skill cover authentication and security?
Yes. The skill requires proper auth/authorization implementation, rate limiting, and credential management, and flags these as must-do items before deployment. See the constraints section for security requirements.

Generated from the current SKILL.md. These answers refresh after source changes.