CtrlK
BlogDocsLog inGet started
Tessl Logo

netlify-mcp-servers

Build, deploy, and secure Model Context Protocol (MCP) servers on Netlify. Use whenever the task involves creating an MCP server, exposing an app or API to AI agents as MCP tools, letting Claude / Cursor / Claude Code call a custom remote server, or adding MCP tools to an existing Netlify site. Covers the MCP SDK + Streamable HTTP transport on a Netlify Function, authentication (single shared secret vs per-user API keys with Netlify Identity), read/write safety, file uploads, and connecting clients. Use even when the user just says "MCP", "tool server for an agent", or "let an AI use my API".

74

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-structured skill body that earns its tokens with non-obvious Netlify-specific gotchas and clean progressive disclosure. Minor conciseness gains are available in the disambiguation paragraph.

Suggestions

Tighten the 'Netlify MCP means two different things' paragraph; the core redirect (hosted Netlify MCP vs your own function) can be stated in 1-2 sentences instead of a full paragraph.

Consider adding a single explicit validate-then-ship checkpoint for the deploy flow (e.g., 'list tools in the Inspector before prod deploy') to push workflow clarity to 5.

DimensionReasoningScore

Conciseness

Mostly lean and dense with non-obvious operational gotchas (406 Accept, 405-to-502, CORS, cross-instance statelessness, secrets-scan failing deploys) that Claude would not already know; the long 'Netlify MCP means two different things' disambiguation paragraph could be trimmed.

4 / 5

Actionability

Provides fully executable, copy-paste-ready code (complete Netlify function, constant-time bearer check, CORS block, rateLimit config) and concrete commands for adding clients and deploying, covering the common cases.

5 / 5

Workflow Clarity

Clear sequenced flow from auth decision through stack, function, tools, safety, rate limiting, uploads, state, clients, to dev/deploy, with verification checkpoints (MCP Inspector, deploy preview for Identity); no explicit validate-fix-retry loop, but the skill is build/deploy rather than destructive/batch.

4 / 5

Progressive Disclosure

SKILL.md is an overview with three well-signaled, one-level-deep real references (authentication.md, connecting-clients.md, file-uploads.md), content appropriately split, and easy navigation.

5 / 5

Total

18

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description with explicit what/when structure and rich natural trigger terms, written in third-person imperative voice. The only soft spot is minor overlap risk on the bare term 'MCP'.

DimensionReasoningScore

Specificity

Lists multiple concrete actions (build/deploy/secure, expose an app or API as MCP tools, add MCP tools to an existing Netlify site) plus specific tech (SDK + Streamable HTTP transport, Netlify Function, auth variants, file uploads, connecting clients), giving comprehensive coverage.

5 / 5

Completeness

Explicitly answers both what (build/deploy/secure with a coverage list) and when via two trigger clauses ('Use whenever the task involves...', 'Use even when the user just says...') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Covers natural phrases users would say ('creating an MCP server', 'letting Claude / Cursor / Claude Code call a custom remote server') and explicitly enumerates raw triggers ('MCP', 'tool server for an agent', 'let an AI use my API'), including synonyms.

5 / 5

Distinctiveness Conflict Risk

Clear niche (your own MCP server on Netlify Functions) with distinct triggers and minimal conflict risk; held at 4 because the bare trigger 'MCP' has minor overlap with Netlify's hosted-MCP and agent-runner skills.

4 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
netlify/context-and-tools
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.