// MCP hub · guides, skills, setup
MCP Servers: Guides, Skills and Setup
Everything on KissMySkills about MCP servers in one place: what they are, how to connect the popular ones to Claude, how to build your own and how to check one is safe before you plug it in.
An MCP server is a small program that gives an AI model access to one system, such as GitHub, Slack, Notion or your own API, through the Model Context Protocol. The server exposes tools (actions), resources (data) and prompts. Claude Desktop, Claude Code, Claude.ai connectors and other MCP clients connect to it locally over stdio or remotely over Streamable HTTP.
// setup guides
MCP server setup guides
Start with the plain-English explainer, then pick the app you want Claude to work with. Each guide covers what the server can do, how to install it and the permissions to watch.
- Start here · explainerWhat is MCP?The Model Context Protocol in plain English: servers, clients, tools and why it mattersRead the guide →
- Guide · GitHubGitHub MCP serverLet Claude read repos, issues and pull requests, and what to allow it to changeRead →
- Guide · SlackSlack MCP serverConnect Claude to channels and threads without handing over the whole workspaceRead →
- Guide · NotionNotion MCP serverSearch, read and update Notion pages and databases from ClaudeRead →
- Guide · FigmaFigma MCP serverPull design context from Figma files into code and specsRead →
- Guide · Google SheetsGoogle Sheets MCP serverRead and write spreadsheet data from ClaudeRead →
- CompareClaude skills vs MCPWhen you need a skill, when you need an MCP server and how they stackRead →
// connect
How to add an MCP server to Claude
Three clients, three ways in. Local servers run on your machine over stdio; remote servers are a URL that speaks Streamable HTTP.
Local servers
- Open Settings, then Developer, then Edit Config.
- Add the server under
mcpServersinclaude_desktop_config.jsonwith its command and arguments. - Restart Claude Desktop and check the tools appear.
Keep tokens out of this file where you can. Use environment variables or the server's own sign-in.
One command
- Local:
claude mcp add my-server -- npx my-mcp-server - Remote:
claude mcp add --transport http my-server https://example.com/mcp - Run
/mcpin a session to check status and sign in.
Add --scope project to share the server with your team through the repository.
Custom connectors
- Open Settings, then Connectors, then Add custom connector.
- Paste the remote MCP server URL.
- Sign in through the server's OAuth screen and enable the tools you need.
Claude.ai connects only to remote servers, so a local stdio server has to be hosted first.
// build
Build your own MCP server
If the system you need has no server yet, building one is a few hundred lines with the official TypeScript or Python SDK. The hard parts are deciding which tools to expose, describing them so the model calls them correctly, handling sign-in for a remote server and testing before anyone relies on it.
# Python, FastMCP from mcp.server.fastmcp import FastMCP mcp = FastMCP("orders") @mcp.tool() def get_order(order_id: str) -> dict: """Look up one order by id. Read-only.""" return lookup(order_id) mcp.run(transport="stdio")
- Test every tool with MCP Inspector before you connect a client:
npx @modelcontextprotocol/inspector. - For a remote server, Cloudflare Workers with OAuth is one of the quickest paths to a URL you can add in Claude.ai.
- Mark write and delete tools clearly and keep read-only tools separate.
// security
MCP security: check before you connect
An MCP server runs with whatever access you give it, and the text it returns goes straight into the model's context. That makes a few risks specific to MCP.
Prompt injection and tool poisoning
Instructions hidden in a tool description or in fetched content can steer the model. Treat every tool result as untrusted data, and review descriptions when a server updates.
Over-broad scopes
A server that only needs to read issues should not hold a token that can delete repositories. Match scopes to tools and split read and write.
Token handling
Remote servers should use OAuth with tokens issued for that server, never pass your upstream token through, and never log tokens or put them in URLs or shared config files.
// skills · $7 each
Skills for building and securing MCP servers
One-time downloads that work inside Claude, Claude Code and other AI chats. Each costs $7.
- AI Skill $7MCP Server BuilderDesign the tools, generate a runnable TypeScript or Python server, test it and deploy it locally or on Cloudflare WorkersView skill →
- AI Skill $7MCP Security ReviewerReview a server or client config for prompt injection, broad scopes, token leaks and unsafe tools, with code fixesView skill →
- AI Skill $7MCP Developer (Xanthe)Architect the tool layer: schemas the model calls correctly, idempotency and tool-count budgetsView skill →
- AI Skill $7Claude Skill CreatorWrite the skill that tells Claude how to use your MCP toolsView skill →
// faq
MCP servers: frequently asked questions
What is an MCP server?
A program that exposes tools, resources and prompts from one system to AI clients through the Model Context Protocol. Claude calls the tools when a task needs them, for example to read a GitHub issue or update a Notion page.
What is the difference between a local and a remote MCP server?
A local server runs on your computer and talks to the client over stdio. A remote server is hosted on the internet, speaks Streamable HTTP and usually signs users in with OAuth. Claude.ai custom connectors need a remote server.
How do I build my own MCP server?
Pick the official TypeScript or Python SDK, define one tool per action with a clear description and input schema, test it in MCP Inspector, then run it locally over stdio or deploy it as a remote server, for example on Cloudflare Workers.
Are MCP servers safe?
They are as safe as the access you give them. Install servers from sources you can identify, pin versions, give each one the narrowest token that works, keep secrets out of config files and treat tool results as untrusted text.
Do I need an MCP server or a Claude skill?
An MCP server gives Claude access to a system. A skill teaches Claude how to do a task. If Claude cannot reach the data, you need MCP; if it can reach it but does the job badly, you need a skill. Many workflows use both.
Build it, then check it, with two $7 skills.
MCP Server Builder writes and deploys the server. MCP Security Reviewer checks it before anyone connects. One-time price, no subscription.