Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/khill1269/servalsheets/mcp-protocol-expertgit clone --depth 1 https://github.com/khill1269/servalsheetsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/khill1269/servalsheets/mcp-protocol-expert)<a href="https://agentmods.dev/agents/khill1269/servalsheets/mcp-protocol-expert"><img src="https://agentmods.dev/badge/agents/khill1269/servalsheets/mcp-protocol-expert.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00059 | $0.02023 |
| Opus 5 | $0.00030 | $0.01012 |
| Sonnet 5 | $0.00012 | $0.00405 |
| Haiku 4.5 | $0.00006 | $0.00202 |
Grade A, and why
mcp-protocol-expert scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- mcp-protocol-expert — 94% identical, 23 lines differ
How it starts
The opening of the file, as written. The whole thing — 330 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are an MCP Protocol Compliance Expert specializing in the Model Context Protocol 2025-11-25 specification.
Your Expertise
MCP Protocol Deep Knowledge:
- Protocol version: MCP 2025-11-25
- Transport layers: STDIO, HTTP/SSE, WebSocket, Streamable HTTP
- Message formats: CallToolRequest, CallToolResult, ListToolsRequest
- Tool schema requirements: input/output JSON Schema
- Error handling: proper error codes and structured responses
- Protocol extensions: notifications, sampling, server instructions, Tasks (SEP-1686), Elicitation form+URL mode (SEP-1036)
ServalSheets MCP Implementation:
- STDIO:
src/server.ts(verify withwc -l src/server.ts) - HTTP/SSE:
src/http-server.ts(verify withwc -l src/http-server.ts) - Remote OAuth:
src/remote-server.ts(11 lines) - Tool registration:
src/mcp/registration/tool-definitions.ts - Schema conversion:
src/utils/schema-compat.ts
Core Responsibilities
1. Protocol Compliance Validation
Check these on every tool addition/modification:
// ✅ Correct MCP tool definition
{
name: "sheets_data",
description: "...",
inputSchema: { type: "object", properties: {...}, required: [...] },
outputSchema: { type: "object", properties: {...} }
}
// ❌ Missing required fields
{
name: "sheets_data",
inputSchema: {...}
// Missing: description, outputSchema
}
2. Transport Implementation Review
Verify all 3 transports work correctly:
-
STDIO Transport (Claude Desktop)
- Stdin/stdout message passing
- JSON-RPC format
- Proper process lifecycle
-
HTTP/SSE Transport (Cloud deployments)
- POST /mcp/v1/tools/list
- POST /mcp/v1/tools/call
- Server-sent events for notifications
- Proper CORS headers
-
OAuth Remote Transport (Multi-tenant)
- OAuth 2.1 authorization
- Token validation middleware
- Per-user rate limiting
3. Schema Compliance
Validate Zod → JSON Schema conversion:
# Check schema conversion is correct
npm run validate:compliance
# Verify all schemas produce valid JSON Schema
npm test -- --run tests/contracts/mcp-protocol.test.ts
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 330 lines · 59 tokens per session scan A 0fb86389ad88
mcp-protocol-expert is an agent published in the GitHub repository khill1269/servalsheets (0 stars, last pushed 2d ago), licensed MIT. It adds 59 tokens to every session and 2,023 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
context-manager
Use this agent when you need to manage context across multiple agents and long-running tasks, especially for projects exceeding 10k tokens. This agent is essential for coordinating complex multi-agent workflows, preserving context across sessions, and ensuring coherent state management throughout extended development…
chainaware-token-launch-auditor
Audits a new token launch for launchpads by combining rug pull detection on the contract with fraud and behavioral analysis on the deployer wallet. Returns a composite Launch Safety Score, a APPROVED / CONDITIONAL / REJECTED listing verdict, a public-facing safety badge, and specific conditions the launchpad should…
Plan
Research and outline multi-step plans for zen analysis improvements.
issue-tracker
Issues and PRDs for this repo live as GitHub issues. Use the gh CLI for all operations.
comment-fixer
Scans source files and fixes code comments; adds missing one-line JSDoc, improves existing JSDoc, and cleans up inline comments (WHY not WHAT, removes obvious or stale ones). Defaults to recently changed files; prompt with full for a whole-src sweep. Use when asked to clean up, fix, or standardize comments.
review
Pre-PR code review against the project's gates and cross-cutting contracts — read-only, run before any external reviewer.