Create, build, and publish Python MCP servers to PyPI — conversationally
mcp-creator exhibits mixed quality. Naming is consistent and action-oriented (get_, update_, check_, scaffold_, add_, build_, publish_, setup_, generate_). All 10 tools have explicit descriptions that are relatively detailed and contextual, better than average. However, parameter documentation is incomplete: while most params have descriptions, several lack type information or have underdescribed constraints. Output schemas are not formally documented anywhere in the source code. Error handling is minimal, most functions return JSON but don't describe recovery paths. The tool compositions are reasonable (distinct responsibilities), but the server conflates complex multi-step workflows (e.g., scaffold_server does code generation, file writing, and project initialization in one call) that could be split. Security considerations are absent, the publish_package tool accepts a PyPI token as a parameter, violating secret-injection patterns. The descriptions are long and procedural rather than concise and LLM-optimized (average ~150 - 250 chars per tool, exceeding the recommended 50 - 200 range). Overall, this is a functional server with decent naming and descriptions, but it lacks the rigor (schemas, error guidance, output documentation, security) expected of production-grade agent tools.
Add a new tool to an existing scaffolded MCP server. Pass the project directory and a JSON tool definition. Creates the tool module, service stub, test, and updates server.py.
Build the MCP server package using 'uv build'. Run this after implementing your tools.
Check if a package name is available on PyPI. Call this first before scaffolding.
Check the user's environment for required tools (uv, git, gh CLI, PyPI token). Call this after get_creator_profile if setup_complete is false. If everything is set up, skip beginner instructions and go straight to building.
Generate a LAUNCHGUIDE.md for MCP Marketplace submission. Creates a formatted file ready to submit at mcp-marketplace.io. Limits: tagline max 100 chars, features max 30 items, tags max 30.
Load the creator's persistent profile — their setup status, GitHub/PyPI usernames, and project history. Call this FIRST in every session. If the profile exists with setup_complete=true, skip all onboarding and go straight to building.
Secret injection violation: publish_package accepts PyPI token as a tool parameter (token: str). Credentials must never appear as parameters, they should be injected server-side via environment variables or vault. Agent traces log all parameters, leaking secrets into logs and prompt history.
No output schemas documented anywhere in source code. Tools return JSON strings, but the structure and fields are not formally specified. LLMs cannot plan downstream calls or extract data reliably without knowing what fields to expect. This violates pattern:tool-schema.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 67 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 55 | - | v1 |
Publish the built package to PyPI using 'uv publish'. Requires a PyPI token — either pass it directly or set UV_PUBLISH_TOKEN env var.
Scaffold a complete, runnable MCP server project. Pass the package name, description, and a JSON array of tool definitions. Each tool def: {name, description, parameters: [{name, type, required, description, default}], returns}. The generated server runs immediately with stub implementations. Set paid=true to add license key gating via the MCP Marketplace SDK. Set paid_tools to a JSON array of tool names to gate (omit to gate all). Set hosting="remote" for an SSE/HTTP server with Dockerfile (default: "local" for stdio).
Initialize git, create a GitHub repo, and push the project. Requires the gh CLI to be installed and authenticated. Run this after publishing to PyPI so the repo URL can be included in the LAUNCHGUIDE.
Update the creator's profile after setup steps or project creation. Call this after: setup completes, a project is published, or GitHub/PyPI info is learned. This persists across sessions so the user never repeats setup.
Incomplete parameter schemas: scaffold_server (tools, env_vars, paid_tools), add_tool (tool), generate_launchguide (features, use_cases, getting_started) all accept JSON strings without specifying the internal structure or constraints. LLMs cannot validate input without a formal schema for the nested JSON.
No error handling or recovery guidance. Functions return JSON with success/error fields, but error responses do not indicate whether failures are retryable, user-fixable, or fatal. Missing pattern:recovery-guide would help agents know what to do next.
Overly complex tool composition: scaffold_server orchestrates code generation, file writing, tool registration, and project initialization in a single call. This violates pattern:tool (one responsibility per tool). Should split into separate tools: scaffold_project, render_tools, write_files.
Descriptions are procedural and verbose (150 - 250 chars average), exceeding LLM-optimized range (50 - 200 chars). Many include imperative instructions ('Call this FIRST', 'Skip all onboarding') that belong in agent orchestration logic, not tool descriptions. This wastes tokens and dilutes signal.
No permission gates or audit trail declarations. Tools like publish_package and setup_github perform sensitive operations (publish to PyPI, push to GitHub) without checking permissions or logging who called them. Violates pattern:permission-gate and pattern:audit-trail.
Missing enums for constrained parameters: hosting in scaffold_server ('local' or 'remote') should be declared as an enum, not a free-form string. category and other dropdown-like fields in generate_launchguide lack enum constraints.
No input validation or sanitization documented. Tools accept file paths (project_dir, output_dir) without mentioning path traversal protections. generate_launchguide accepts free-form text without escape or sanitization guidelines. Violates pattern:tool-gateway.
Parameter dependencies and mutual exclusions not documented: update_creator_profile has 5 optional params (setup_complete, github_username, pypi_username, default_output_dir, add_project), but the description does not clarify whether all, some, or one should be provided. generate_launchguide has tools_summary marked deprecated but still accepted, creating ambiguity.