mcp-best-practicesBuild, harden, and debug production MCP servers with the TypeScript SDK. Use when writing or reviewing an MCP server - transports, tool schemas, errors, OAuth, token bloat, SDK migrations, MCP Apps, Registry. Assumes a server already exists.
Install via ClawdBot CLI:
clawdbot install tenequm/mcp-best-practicesGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.ssh/id_rsaSends data to undocumented external endpoint (potential exfiltration)
post → https://github.com/modelcontextprotocol/ext-apps/blob/main/specification/2026-01Potentially destructive shell commands in tool definitions
rm -rf /Accesses system directories or attempts privilege escalation
sudo rmGenerated May 5, 2026
A SaaS offering multiple AI-powered tools (e.g., data analysis, CRM integration). Each customer gets an isolated MCP server instance per request using the stateless pattern, ensuring no cross-tenant data leakage. Tools are registered per customer based on their subscription tier.
An internal AI assistant for HR, IT, and finance that can query databases, update tickets, and run scripts. Uses stdio transport for on-premise deployment with strict ACL annotations (destructiveHint, readOnlyHint) to prevent unauthorized modifications.
A lightweight MCP server deployed on Cloudflare Workers using WebStandardStreamableHTTPServerTransport with stateless session handling. Handles public-facing APIs like weather or translation, optimized for low latency and no persistent sessions.
An MCP server that provides product recommendations via tools and pushes real-time inventory changes through SSE subscriptions. Uses stateful transport with session tracking for long-lived connections and structuredContent for rich product responses.
An MCP server for analyzing anonymized patient data, registered in the MCP Registry for use by authorized medical AI agents. Tools enforce read-only access and outputSchema for structured results, with security best practices to meet HIPAA guidelines.
Charge customers based on the number of tool invocations (e.g., $0.01 per search_tweets call). Use annotations like idempotentHint to ensure idempotent billing, and implement rate limiting via toolAnnotations to prevent abuse.
Offer Basic ($10/mo, 3 tools) and Pro ($50/mo, 10 tools, streaming). Dynamically register tools based on subscription using the McpServer per request pattern. Extensions like MCP Apps can provide interactive UIs for higher tiers.
Operate an MCP Registry where developers publish tools with outputSchema and annotations. Charge a listing fee and revenue share (e.g., 20%) on tool usage. Businesses discover and integrate tools via the Registry.
💬 Integration Tip
Start by defining your transport strategy (stateless vs stateful) before writing any tool logic; this ensures your architecture scales and avoids common pitfalls like session leaks.
Scored Oct 6, 2026
Calls external URL not in known-safe list
https://spec.modelcontextprotocol.ioAI Analysis
This is a legitimate technical documentation skill about MCP server development best practices. The 'signals' appear to be false positives from pattern matching on example code snippets (like SSH key paths, rm commands, and spec URLs) that are part of instructional content, not actual malicious functionality. The skill does not execute code or exfiltrate data.
Audited Apr 16, 2026 · audit v1.0
You are a professional writer, skilled in writing all kinds of materials. Markdown is the exclusive format for your writing outputs.rrent user query.The othe...
AI长篇网文创作技能包。用于解决长篇网络小说创作中的核心痛点:上下文丢失、文风不一致、设定冲突、节奏失控、多线混乱、质量不稳、读者反馈无法内化。触发场景包括:开始新书、规划大纲、撰写章节、管理伏笔、检测冲突、读者反馈分析、批量创作质量控制。
Deprecated redirect skill that routes legacy 'content creator' requests to the correct specialist. Use when a user invokes 'content creator', asks to write a...
Refine academic writing for computer science research papers targeting top-tier venues (NeurIPS, ICLR, ICML, AAAI, IJCAI, ACL, EMNLP, NAACL, CVPR, WWW, KDD, SIGIR, CIKM, and similar). Use this skill whenever a user asks to improve, polish, refine, edit, or proofread academic or research writing — including paper drafts, abstracts, introductions, related work sections, methodology descriptions, experiment write-ups, or conclusion sections. Also trigger when users paste LaTeX content and ask for writing help, mention "camera-ready", "rebuttal", "paper revision", or reference any academic venue or conference. This skill handles both full paper refinement and section-by-section editing.
AI写作助手 Premium | 智能写作、改写、润色。支持10种写作风格,AI查重,SEO优化。
AI写作助手 v2.1 | AI Writing Assistant. 支持10种写作风格、语法检查、润色建议、素材库、Markdown导出、协作编辑、版本管理。触发词:写作、写、文章、文案。