Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/phuonghx/aim-cli/mcp-buildernpx skills add phuonghx/aim-cli --skill mcp-buildergit clone --depth 1 https://github.com/phuonghx/aim-cliWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00080 | $0.01202 |
| Opus 5 | $0.00040 | $0.00601 |
| Sonnet 5 | $0.00016 | $0.00240 |
| Haiku 4.5 | $0.00008 | $0.00120 |
Grade A, and why
mcp-builder scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 162 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Building MCP Servers
The Model Context Protocol is the wiring that lets an AI system reach external tools and data through a stable contract. A well-built server makes that contract obvious; a poorly built one leaves the model guessing. The notes below are about getting the design right.
The Three Building Blocks
A server exposes some mix of three things:
| Block | What it gives the model |
|---|---|
| Tools | Functions it can call to act |
| Resources | Data it can read |
| Prompts | Reusable prompt templates |
Laying Out The Server
A minimal project
my-server/
├── src/
│ └── index.ts # entry — McpServer from the TS SDK
├── package.json # depends on @modelcontextprotocol/sdk
└── tsconfig.json
The TypeScript SDK is @modelcontextprotocol/sdk, which exports McpServer. The Python SDK is the mcp package — install it with pip install "mcp[cli]", and reach for FastMCP from mcp.server.fastmcp.
Transports
| Transport | Where it fits |
|---|---|
| stdio | Local processes, CLI-launched servers |
| Streamable HTTP | Remote and web-hosted servers (this superseded the old HTTP+SSE transport) |
The current spec (revision 2025-06-18) standardizes exactly these two. WebSocket is not a standard transport. On any Streamable HTTP server, check the Origin header before trusting a request.
Designing Tools
What a good tool looks like
| Trait | What it means |
|---|---|
| Verb-first name | fetch_invoice, archive_thread — the action is in the name |
| One job | It does a single thing and does it cleanly |
| Typed input | A schema with types and per-field descriptions |
| Predictable output | A consistent, parseable result shape |
Shaping the input schema
| Piece | Needed? |
|---|---|
| Top-level type | Yes — object |
| Properties | Define every parameter |
| Required list | Name the mandatory ones |
| Descriptions | Write them for a human reader |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 162 lines · 80 tokens per session scan A aa72b1c24b93
mcp-builder is a skill published in the GitHub repository phuonghx/aim-cli (1 stars, last pushed 2mo ago), licensed MIT. It adds 80 tokens to every session and 1,202 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
hs-release
Cut a core Hindsight release (vX.Y.Z) and open the changelog + blog PR. Use when asked to cut/start a release, bump the version, or publish a new Hindsight version.
hindsight-local
Store user preferences, learnings from tasks, and procedure outcomes. Use to remember what works and recall context before new tasks. (user).
research-repository
Build a repository that makes findings findable, reusable, and cumulative across teams. Use when the same research keeps getting redone. For synthesising one study, use affinity-diagram.
design-negotiation
Advocate for design quality, scope, and timeline with partners and leadership using evidence and shared goals. Use in the conversation itself. For the commercial vocabulary behind it, use business-design (ux-strategy).
user-persona
Build research-grounded personas with goals, frustrations, and behavioural patterns. Use when decisions need a consistent user reference. For one session's emotional snapshot use empathy-map; for motivation framing use jobs-to-be-done.
version-control-strategy
Define version control for design files, components, and libraries — branching, naming, and release. Use when file history is chaotic. For design system contribution rules, use design-system-governance (design-systems).