CtrlK
BlogDocsLog inGet started
Tessl Logo

build-mcpb

This skill should be used when the user wants to "package an MCP server", "bundle an MCP", "make an MCPB", "ship a local MCP server", "distribute a local MCP", discusses ".mcpb files", mentions bundling a Node or Python runtime with their MCP server, or needs an MCP server that interacts with the local filesystem, desktop apps, or OS and must be installable without the user having Node/Python set up.

68

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable skill body: complete executable code, concrete per-platform build pipelines, explicit validation commands, and clean offloading of manifest and security detail into real one-level-deep reference files. Its only real weaknesses are repetition of the no-sandbox/local-vs-remote points and the lack of an explicitly ordered workflow with error-recovery guidance.

DimensionReasoningScore

Conciseness

The body is mostly lean with concrete examples and no padding of known concepts, but the no-sandbox point is repeated three times ("Sandboxing is entirely your job", the dedicated "MCPB has no sandbox — security is on you" section, "If you came here expecting filesystem/network scoping... it doesn't exist") and the local-vs-remote guidance appears twice in the intro. Anchor 4 (efficient, minor instances that could be trimmed) fits; not 5 due to this repetition.

4 / 5

Actionability

Fully executable throughout: a complete TypeScript stdio server, a full manifest.json example, copy-paste build commands for both Node (esbuild, mcpb pack) and Python (pip install -t server/vendor), and concrete init/validate/pack/sign/inspector commands. Matches anchor 5 (copy-paste ready, covers the common cases).

5 / 5

Workflow Clarity

The topical sequence (manifest → server code → build → test) is clear and validation checkpoints exist ("validates manifest.json against the schema", mcpb validate, "Test on a machine without your dev toolchain"), but steps are not explicitly ordered and there is no error-recovery loop for validation failures. Anchor 4 fits better than 5, which requires explicit sequencing with feedback loops.

4 / 5

Progressive Disclosure

A concise overview body with two one-level-deep, well-signaled references ("See references/manifest-schema.md for all fields", "references/local-security.md is mandatory reading") — both verified to exist and match their descriptions — plus a closing reference file list. Matches anchor 5.

5 / 5

Total

18

/

20

Passed

Description

81%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A trigger-rich, highly distinct description that makes clear when to invoke the skill, using third-person voice and natural user phrasing including the .mcpb extension. Its one weakness is that the "what" — building a runtime-bundled, single-file installable MCP server package — is only implied through quoted trigger verbs rather than stated as a capability.

Suggestions

Open with a one-sentence capability statement in third person, e.g. "Packages a local MCP server with its Node/Python runtime into a single installable .mcpb file.", before the when-clause, so the "what" is explicit rather than implied.

State the core deliverables concretely (writes manifest.json, bundles server + dependencies, produces a signed .mcpb archive) to lift specificity beyond the verbs quoted from user phrasing.

DimensionReasoningScore

Specificity

Concrete actions like "package an MCP server" and "bundling a Node or Python runtime" appear, but only as quoted user intents inside when-clauses; the skill's capabilities are never stated directly and coverage is not comprehensive. This matches anchor 3 (names domain and 1-2 concrete actions) better than anchor 4, whose examples list actions as capabilities.

3 / 5

Completeness

"When" is explicit and rich ("This skill should be used when the user wants to..."), and "what" is conveyed through the quoted verbs (package/bundle into an installable artifact), but no capability sentence states what the skill produces. Between anchors 4 and 5 — the "what" is present but not explicit, so 4.

4 / 5

Trigger Term Quality

Comprehensive natural trigger coverage with synonyms and the file extension: "package an MCP server", "bundle an MCP", "make an MCPB", "ship a local MCP server", "distribute a local MCP", ".mcpb files", "installable without the user having Node/Python set up". Matches anchor 5 exactly.

5 / 5

Distinctiveness Conflict Risk

Clear niche (local MCP packaging) with distinct triggers (".mcpb", "bundle a runtime") and explicit scoping away from remote/cloud servers, minimizing conflict with adjacent MCP-building skills. Matches anchor 5.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
anthropics/claude-plugins-official
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.