Tested demoQuality 98/100

yonatangross/orchestkit/plugins/ork/skills/mcp-patterns/SKILL.md

mcp-patterns

MCP server building, advanced patterns, and security hardening. Use when building MCP servers, implementing tool handlers, choosing a transport, adding OAuth authentication, wiring MCP Apps UI with @mcp-ui, hardening MCP security, or debugging MCP integrations.

Source repository stars
223
Declared platforms
1
Static risk flags
0
Last source update
2026-08-24
Source checked
2026-08-25

Decision brief

What it does: where it fits

Patterns for building, composing, and securing Model Context Protocol servers. Based on the 2025-11-25 specification — the latest stable release maintained by the Agentic AI Foundation (Linux Foundation), co-founded by Anthropic, Block, and OpenAI.

Best for

  • Use when building MCP servers, implementing tool handlers, choosing a transport, adding OAuth authentication, wiring MCP Apps UI with @mcp-ui, hardening MCP security, or debugging MCP integrations.

Not for

  • No lifecycle management (connection/resource leaks on shutdown)
  • Missing input validation on tool arguments
Controlled single-run demoChecked 2026-08-20

What changed when the Skill was used

In this controlled same-task single run, enabling mcp-patterns changed the output from 2647 non-whitespace characters and 18 headings to 2378 characters and 12 headings. Matches among 8 signals extracted from the pinned source changed from 0 to 0. Both actual outputs are shown; this is a structural observation, not a quality score or a universal performance claim.

Same test task

Create a design direction and implementation handoff for a developer tool that compares two API responses. Prioritize the repeated user workflow and responsive behavior. The deliverable must specifically reflect this user intent: MCP server building, advanced patterns, and security hardening. Use when building MCP servers, implementing tool handlers, choosing a transport, adding OAuth authentication, wiring MCP Apps UI with @mcp-ui, hardening MCP security, or debugging MCP integrations.

Without the Skill
Screenshot of the actual model output for mcp-patterns without the Skill

Baseline: 2647 non-whitespace characters, 18 headings, and 61 list items.

With the Skill
Screenshot of the actual model output for mcp-patterns with the Skill

With Skill: 2378 non-whitespace characters, 12 headings, and 77 list items.

ObservationWithout SkillWith Skill
Source-signal coverage0/8: none0/8: none
Output structure2647 chars · 18 headings · 61 list items · 0 code blocks2378 chars · 12 headings · 77 list items · 0 code blocks
Verification and caution signals7 verification signals · 11 risk/limitation signals7 verification signals · 5 risk/limitation signals

A prompt you can use

Use the mcp-patterns Skill pinned at 4fb82d5a3e87 for my task. Follow its source-specific constraints around `mcp-patterns`, `patterns`, `decision`, `which`, then return the finished deliverable with explicit assumptions, verification, failure conditions, and limits. Do not treat the Skill text as a factual source or claim that a single demonstration proves universal performance.

Method and limitationsExpand

Test method

  • Baseline and treatment used the same task, model (gpt-5.3-codex-low), and runner; the only planned difference was whether the complete target Skill text was injected.
  • The treatment used snapshot c1b44d376dc90bef276fc307dae033e8e9cd2a89; the current source commit 4fb82d5a3e87be7395fab3a7810f5824f38c2a57 was verified against content hash 0c4fb7f3697c. The baseline explicitly prohibited loading any Skill or external rule file.
  • The same deterministic script counted characters, headings, lists, code blocks, verification terms, caution terms, and source signals in both artifacts. Source signals: `mcp-patterns`, `patterns`, `decision`, `which`, `quick`, `reference`, `decisions`, `governance`.
  • The visuals are local screenshots of the actual Markdown artifacts in a fixed 1200 × 800 evidence canvas, not recreated product mockups. Raw JSON artifacts and request records are retained in the research directory.

Do not over-read this demo

  • This is one controlled demonstration per condition, not a multi-run statistical benchmark; the model is stochastic.
  • Character, structure, and keyword counts show observable differences but cannot by themselves prove correctness, originality, or business impact.
  • The task is a representative test designed for repeatability, not every real-world use of the Skill; rerun after a material source change.
Editorial review
SkillSignal editorial
Runner
Cursor Agent 2026.08.04-aaa8809
Model
gpt-5.3-codex-low
Refresh due
2026-11-18
Reviewed commit
4fb82d5a3e87be7395fab3a7810f5824f38c2a57
Test snapshot
c1b44d376dc90bef276fc307dae033e8e9cd2a89

Compatibility matrix

Platform support, with evidence labels

PlatformStatusEvidenceWhat to check
CodexNot declaredNo explicit evidencePortability before use
Claude CodeDeclaredSource recordInstall path and trigger
CursorNot declaredNo explicit evidencePortability before use
Gemini CLINot declaredNo explicit evidencePortability before use
Open the compatibility checker

Installation

Inspect first. Install second.

The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

Source-detected install commandSource
npx skills add https://github.com/yonatangross/orchestkit --skill "plugins/ork/skills/mcp-patterns"
Safe inspection promptEditorial

Inspect the Agent Skill "mcp-patterns" from https://github.com/yonatangross/orchestkit/blob/4e5c1327b7d7902022ee69328e12db1f6a88f390/plugins/ork/skills/mcp-patterns/SKILL.md at commit 4e5c1327b7d7902022ee69328e12db1f6a88f390. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

Workflow

What the source asks the agent to do

  1. 01

    Decision Tree — Which Rule to Read

    Review the “Decision Tree — Which Rule to Read” section in the pinned source before continuing.

    Review and apply the “Decision Tree — Which Rule to Read” source section.
  2. 02

    Quick Reference

    Total: 14 rules across 6 categories

    Total: 14 rules across 6 categories
  3. 03

    Key Decisions

    Review the “Key Decisions” section in the pinned source before continuing.

    Review and apply the “Key Decisions” source section.
  4. 04

    Spec & Governance

    Protocol: Model Context Protocol, spec version 2025-11-25 (latest stable)

    Protocol: Model Context Protocol, spec version 2025-11-25 (latest stable)Governance: Agentic AI Foundation (Linux Foundation, Dec 2025)Platinum members: AWS, Anthropic, Block, Bloomberg, Cloudflare, Google, Microsoft, OpenAI
  5. 05

    Feature Maturity

    Review the “Feature Maturity” section in the pinned source before continuing.

    Review and apply the “Feature Maturity” source section.

Permission review

Static risk signals and limitations

No configured static risk pattern was detected

This is not proof of safety. Runtime behavior, indirect dependencies, and hidden external systems are outside the static scan.

Evidence record

Why each signal appears

EvidenceSourceComputedTestedEditorial
SignalValueEvidence typeMeaning
Quality score98/100ComputedDocumentation, specificity, maintenance, and trust rules
Repository stars223SourceRepository attention, not individual Skill quality
Compatibility1 platformsSourceDeclared in the catalog source record
Usage guidetested outcome pageTestedGenerated or reviewed according to the visible evidence level

Pinned source

Provenance and original SKILL.md

Repository
yonatangross/orchestkit
Skill path
plugins/ork/skills/mcp-patterns/SKILL.md
Commit
4e5c1327b7d7902022ee69328e12db1f6a88f390
License
MIT
Collected
2026-08-25
Default branch
main
View the original SKILL.md

MCP Patterns

Patterns for building, composing, and securing Model Context Protocol servers. Based on the 2025-11-25 specification — the latest stable release maintained by the Agentic AI Foundation (Linux Foundation), co-founded by Anthropic, Block, and OpenAI.

Scaffolding a new server? Use Anthropic's mcp-builder skill (claude install anthropics/skills) for project setup and evaluation creation. This skill focuses on patterns, security, and advanced features after initial setup.

Deploying to Cloudflare? See the building-mcp-server-on-cloudflare skill for Workers-specific deployment patterns.

Pin mcp<2 until you migrate. Every Python snippet in this skill targets the v1 SDK (from mcp.server.fastmcp import FastMCP). The Python SDK released 2.0.0, pip install mcp now resolves to it, and upstream's own README says to keep a <2 upper bound on your requirement until you have migrated. FastMCP does not appear anywhere in the 2.0 README, so treat these snippets as v1-only rather than assuming they still apply. v1.x continues to receive critical bug and security fixes on its own branch. Verified 2026-07-31. Migration guide: https://py.sdk.modelcontextprotocol.io/migration/

Decision Tree — Which Rule to Read

What are you building?
│
├── New MCP server
│   ├── Setup & primitives ──────► rules/server-setup.md
│   ├── Transport selection ─────► rules/server-transport.md
│   └── Scaffolding ─────────────► mcp-builder skill (anthropics/skills)
│
├── Authentication & authorization
│   └── OAuth 2.1 + OIDC ───────► rules/auth-oauth21.md
│
├── Advanced server features
│   ├── Tool composition ────────► rules/advanced-composition.md
│   ├── Resource caching ────────► rules/advanced-resources.md
│   ├── Elicitation (user input) ► rules/elicitation.md
│   ├── Sampling (agent loops) ──► rules/sampling-tools.md
│   └── Interactive UI ──────────► rules/apps-ui.md
│
├── Client-side consumption
│   └── Connecting to servers ───► rules/client-patterns.md
│
├── Security hardening
│   ├── Prompt injection defense ► rules/security-injection.md
│   └── Zero-trust & verification ► rules/security-hardening.md
│
├── Testing & debugging
│   └── Inspector + unit tests ──► rules/testing-debugging.md
│
├── Discovery & ecosystem
│   └── Registries & catalogs ──► rules/registry-discovery.md
│
└── Browser-native tools
    └── WebMCP (W3C) ───────────► rules/webmcp-browser.md

Quick Reference

CategoryRuleImpactKey Pattern
Serverserver-setup.mdHIGHFastMCP lifespan, Tool/Resource/Prompt primitives
Serverserver-transport.mdHIGHstdio for CLI, Streamable HTTP for production
Authauth-oauth21.mdHIGHPKCE, RFC 8707 resource indicators, token validation
Advancedadvanced-composition.mdMEDIUMPipeline, parallel, and branching tool composition
Advancedadvanced-resources.mdMEDIUMResource caching with TTL, LRU eviction, lifecycle
Advancedelicitation.mdMEDIUMServer-initiated structured input from users
Advancedsampling-tools.mdMEDIUMServer-side agent loops with tool calling
Advancedapps-ui.mdMEDIUMInteractive UI via MCP Apps + @mcp-ui/* SDK
Clientclient-patterns.mdMEDIUMTypeScript/Python MCP client connection patterns
Securitysecurity-injection.mdHIGHDescription sanitization, encoding normalization
Securitysecurity-hardening.mdHIGHZero-trust allowlist, hash verification, rug pull detection
Qualitytesting-debugging.mdMEDIUMMCP Inspector, unit tests, transport debugging
Ecosystemregistry-discovery.mdLOWOfficial registry API, server metadata
Ecosystemwebmcp-browser.mdLOWW3C browser-native agent tools (complementary)

Total: 14 rules across 6 categories

Key Decisions

DecisionRecommendation
Transportstdio for CLI/Desktop, Streamable HTTP for production (SSE deprecated)
LanguageTypeScript for production (better SDK support, type safety)
AuthOAuth 2.1 with PKCE (S256) + RFC 8707 resource indicators
Server lifecycleAlways use FastMCP lifespan for resource management
Error handlingReturn errors as text content (Claude can interpret and retry)
Tool compositionPipeline for sequential, asyncio.gather for parallel
Resource cachingTTL + LRU eviction with memory cap
Tool trust modelZero-trust: explicit allowlist + hash verification
User inputElicitation for runtime input; never request PII via elicitation
Interactive UIMCP Apps with @mcp-ui/* SDK; sandbox all iframes
Token handlingNever pass through client tokens to downstream services
Large resultsUse _meta["anthropic/maxResultSizeChars"] annotation (up to 500K) for results that lose meaning when truncated (CC 2.1.91)

Spec & Governance

  • Protocol: Model Context Protocol, spec version 2025-11-25 (latest stable)
  • Governance: Agentic AI Foundation (Linux Foundation, Dec 2025)
  • Platinum members: AWS, Anthropic, Block, Bloomberg, Cloudflare, Google, Microsoft, OpenAI
  • Adoption: 10,000+ servers; Claude, Cursor, Copilot, Gemini, ChatGPT, VS Code
  • Spec URL: https://modelcontextprotocol.io/specification/2025-11-25
  • 2026 model: Working Groups and Interest Groups are now the primary vehicle for protocol evolution (no more milestone-based releases). Enterprise readiness lands as extensions, not core spec changes.

Feature Maturity

FeatureSpec VersionStatus
Tools, Resources, Prompts2024-11-05Stable
Streamable HTTP transport2025-03-26Stable (replaces SSE)
OAuth 2.1 + Elicitation (form)2025-06-18Stable
Sampling with tool calling2025-11-25Stable
Elicitation URL mode2025-11-25Stable
MCP Apps (UI extension)2026-01-26Extension (ext-apps)
WebMCP (browser-native)2026-02-14W3C Community Draft

SDK landscape (2026-Q2)

PackageWhat it isWhen to use
mcp (PyPI) >=1.27Official Python SDK — includes the FastMCP helper, transport adapters, InspectorNew Python servers. This is the canonical package.
@modelcontextprotocol/sdk (npm) >=1.29Official TypeScript SDKNew TS servers
fastmcp (PyPI)Standalone fork by jlowin — predates mcp; API-compatible but diverges on lifespan and middlewareExisting projects pinned to it. New projects should prefer mcp.

The fastmcp fork and the mcp.server.fastmcp module are not the same package. Imports and pyproject.toml entries must agree or stacktraces become cryptic.

Debugging with Claude Code

Pass --mcp-debug to Claude Code when troubleshooting server wiring — it surfaces the raw JSON-RPC frames, handshake failures, and tool-registration events that the default logger swallows:

claude --mcp-debug "query the local test server"
# or per-session:
export CLAUDE_MCP_DEBUG=1

Use alongside the MCP Inspector (npx @modelcontextprotocol/inspector <cmd>) — Inspector gives you the client-side frame view, --mcp-debug gives you what Claude actually saw.

CC 2.1.128 — reconnect tool summarization: when a server reconnects mid-session, re-announced tools are summarized as mcp__<server>__* (N tools re-registered) instead of being enumerated line-by-line. Use the initial connect event as the source of truth for tool inventory; treat reconnect summaries as deltas only. See references/mcp-audit-runbook.md for grep recipes that work across both formats.

CC 2.1.133 — MCP OAuth honors HTTP(S)_PROXY / NO_PROXY / mTLS: the full MCP OAuth flow (discovery, dynamic client registration, token exchange, token refresh) now respects standard proxy and client-certificate env vars end-to-end. Enterprise deployments behind corporate proxies no longer need OAuth-specific workarounds — the same HTTPS_PROXY / NO_PROXY / NODE_EXTRA_CA_CERTS config that already routes MCP transport now also routes auth. See configure/references/cc-version-settings.md (CC 2.1.133 section) for the env-var example. The companion deployment skill building-mcp-server-on-cloudflare can drop any prior "proxy-aware OAuth requires manual handling" caveat at this floor.

CC 2.1.169 — managed MCP policies enforced everywhere: enterprise allowedMcpServers/deniedMcpServers now apply on reconnect, IDE-typed configs, --mcp-config servers in the first session after install, and before remote settings load (previously all four paths skipped enforcement). Orgs without remote settings also get faster cold starts. If a previously-working server stops connecting after 2.1.169, check the managed policy before debugging the server.

CC 2.1.163 — stdio servers get CLAUDE_CODE_SESSION_ID: on --resume, stdio MCP servers now receive the same CLAUDE_CODE_SESSION_ID env var that hooks and Bash already get. Read it inside the server to correlate logs/telemetry across resumed sessions instead of minting your own session key — but never store auth tokens keyed off it (see Common Mistake #7).

Example

from mcp.server.fastmcp import FastMCP

mcp = FastMCP("my-server")

@mcp.tool()
async def search(query: str) -> str:
    """Search documents. Returns matching results."""
    results = await db.search(query)
    return "\n".join(r.title for r in results[:10])

Common Mistakes

  1. No lifecycle management (connection/resource leaks on shutdown)
  2. Missing input validation on tool arguments
  3. Returning secrets in tool output (API keys, credentials)
    • CC 2.1.161 mitigates this at the CLI layer: claude mcp list/get/add no longer expands ${VAR} references and redacts credential headers and URL secrets in terminal output — but server code must still never return secrets in tool results. /mcp also collapses never-signed-in connectors behind a "Show unused connectors" row.
    • CC 2.1.186 adds claude mcp login <name> / claude mcp logout <name> for OAuth-backed servers (HTTP/SSE/connector). Pass --no-browser to print the authorization URL instead of opening a browser — the supported path for SSH/headless/remote sessions (paste the redirect URL back when prompted), so interactive-only auth never blocks automated setup.
  4. Unbounded response sizes without _meta annotation — use _meta["anthropic/maxResultSizeChars"] to declare intentionally large results (DB schemas, API specs) so clients/hooks don't truncate them
  5. Trusting tool descriptions without sanitization (injection risk)
  6. No hash verification on tool invocations (rug pull vulnerability)
  7. Storing auth tokens in session IDs (credential leak)
  8. Blocking synchronous code in async server (use asyncio.to_thread())
  9. Using SSE transport instead of Streamable HTTP (deprecated since March 2025)
  10. Passing through client tokens to downstream services (confused deputy)

Ecosystem

ResourceWhat For
mcp-builder skill (anthropics/skills)Scaffold new MCP servers + create evals
building-mcp-server-on-cloudflare skillDeploy MCP servers on Cloudflare Workers
@mcp-ui/* packages (npm)Implement MCP Apps UI standard
MCP RegistryDiscover servers: https://registry.modelcontextprotocol.io/
MCP InspectorDebug and test servers interactively

Related Skills

  • ork:llm-integration — LLM function calling patterns
  • ork:security-patterns — General input sanitization and layered security
  • ork:api-design — REST/GraphQL API design patterns

Frequently asked questions

What to verify before installation and use

What does the mcp-patterns source document cover?

Patterns for building, composing, and securing Model Context Protocol servers. Based on the 2025-11-25 specification — the latest stable release maintained by the Agentic AI Foundation (Linux Foundation), co-founded by Anthropic, Block, and OpenAI.

How do I install mcp-patterns?

The source record exposes this install command: npx skills add https://github.com/yonatangross/orchestkit --skill "plugins/ork/skills/mcp-patterns". Inspect the command and pinned source before running it.

Which Agent platforms does the source record declare?

The pinned source record declares support for: claude code.

Alternatives

Compare before choosing

Computed 100147

oaustegard/claude-skills

featuring

Generate hierarchical _FEATURES.md files that describe what a codebase DOES from a user/consumer perspective, anchored to source symbols via tree-sitting. Supports large complex codebases through feature-driven decomposition into sub-feature files. Uses a multi-pass synthesis: orientation → detail → overview rewrite. Use when someone says "what does this do", "document features", "feature inventory", "_FEATURES.md", or needs to understand a codebase's purpose before modifying it. Complements tre

Computed 1008

narrative-io/narrative-skills-marketplace

design-analysis

Translate a fuzzy analytical question into a rigorous investigation plan. Interrogates the ask, grounds the plan in the available data dictionary, applies analytical best practices, and produces a structured brief of query specifications for a downstream query-writing skill. Plans, does not write SQL. Use when: "why did X drop", "is there a relationship between A and B", "who are our highest-value customers", "what's driving the change in Y", "investigate this trend", "design an analysis for", "

Computed 9980

vasilyu1983/AI-Agents-public

qa-testing-ios

Guides iOS testing with XCTest, XCUITest, Swift Testing, simctl, and xcresult. Use when choosing destinations, controlling flakes, or parsing test artifacts for native apps.

Computed 9965

brucesongs/kali-claw

insecure-design

Insecure Design (OWASP A06:2025) focuses on security flaws in system architecture and design phases, rather than code implementation-level bugs.