mcp-apps-builder
Build, modify, debug, migrate, review, or verify TypeScript MCP servers and MCP Apps with mcp-use. Use for tools, resources, prompts, middleware, Vi…
它会碰到什么
扫了多少9 个文本文件,33 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Build with mcp-use
Treat the installed mcp-use package, its exported types, generated declarations, and the project's existing code as the source of truth. Inspect the installed version before choosing APIs or changing code.
Workflow
- Inspect
package.json, the server entry, exported tool refs,mcp-env.d.ts,views/,skills/, and the installedmcp-useversion. - Scaffold a new stable project with
create-mcp-use-app@latestand the appropriate template. Match the package version or dist-tag when working on beta, canary, or an existing versioned project. - Read only the references needed for the task:
- [Server](references/server.md) for tools, resources, prompts, MCP middleware, request context, and result envelopes.
- [Views](references/views.md) for interactive MCP Apps, React hooks, model context, host capabilities, assets, and CSP.
- [Authentication](references/auth.md) for OAuth providers, verified identity, scopes, permissions, and authorization.
- [Skills over MCP](references/skills-over-mcp.md) when a server should ship reusable workflows alongside its tools.
- [Advanced features](references/advanced-features.md) for OpenAPI, proxying, notifications, subscriptions, and elicitation.
- [Migration](references/migration.md) only when retired or compatibility-only imports, helpers, registration shapes, UI patterns, or session assumptions are present.
- [Verification](references/verification.md) before reporting implementation work complete.
- Implement against installed types. Prefer the framework's current conventions over copied examples or historical changelogs.
- Validate the smallest real lifecycle that proves the changed behavior, then expand checks in proportion to risk.
Core invariants
- Import server APIs from
mcp-use, React APIs frommcp-use/react, and OAuth provider adapters from theirmcp-use/oauth/*subpaths. - Define tool arguments with
inputSchema. AddoutputSchemafor structured results and every View-bound tool. - Return raw MCP result envelopes. A successful schema-backed tool must include matching
structuredContent; an expected failure may returnisError: truewith model-readablecontent. - Put each View at
views/<name>/view.tsxand bind it withview: { name: "<name>" }. - Export every statically declared tool ref consumed by a View. Default-export the server entry used by
mcp-use dev,build, andstart. - Keep identity and mutable workflow state request-scoped or in an external store. Treat client-reported metadata as unverified.
- Consider Skills over MCP when a server exposes a repeatable, multi-step workflow that would otherwise inflate tool descriptions.
Guardrails
- Do not invent exports, configuration fields, or callback shapes. Confirm uncertain details in installed declarations or source.
- Do not preserve APIs that are absent from the installed version merely because they appear in an existing project.
- Do not return a plain domain object from a tool callback.
- Do not bind a View without a matching
outputSchemaandstructuredContentresult. - Do not use module globals for cross-request identity, elicitation continuity, or durable business state.
- Do not claim success from a source build alone when types, package exports, authentication, or interactive behavior changed.
- Do not deploy or mutate external systems unless the user explicitly requests it.
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。