mcp-bundle
Claude Code plugin and GitHub Actions workflow for packaging MCP servers into MCPB bundles. Detects servers, generates manifests, validates specs, and automates CI/CD packaging.
Install / Use
claude mcp add zircote -- npx -y github:zircote/mcp-bundleIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
AutomationSupported Platforms
Our assessment of mcp-bundle
mcp-bundle scores 77/100 on our quality scale, 2563rd of 2,868 Automation skills we index.
Its MCP Server is 11 KB long, well organised into 24 sections with 5 code examples: a thorough specification that gives an agent plenty to work with.
It has 3 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated about 7 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.
- Our last check on 2026-09-23 found the source still online.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 86/100, with 2 cautions from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.
AI review by kimi-k2.7-code on 2026-09-24. Automated pattern scan on 2026-09-24. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
mcp-bundle compared with similar skills
All 4 of these similar skills score higher than mcp-bundle; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| mcp-bundle (this skill)by zircote | 77 | 3 | 7mo ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 91.6k | 20d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.4k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.2k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 85.8k | today | MCP Server |
Frequently asked questions
- How do I install mcp-bundle?
- Run
claude mcp add zircote -- npx -y github:zircote/mcp-bundle. The install tabs above show the steps for each supported agent. - Which AI agents does mcp-bundle work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is mcp-bundle safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It is MIT-licensed and scores 86/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is mcp-bundle still maintained?
- The repository was last updated about 7 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.
Skill content
View source on GitHubmcp-bundle
A Claude Code plugin and GitHub Actions workflow for generating MCPB (MCP Bundle) packages from MCP server projects.
Prerequisites
- An MCP server project using stdio transport
- Node.js 20+ (for Node.js server types and the
mcpbCLI) jqinstalled (used by validation scripts)- For local testing:
npm install -g @anthropic-ai/mcpb
What It Does
/mcpbskill: Detects MCP server projects, generatesmanifest.json, creates bundle directory structure, validates against the MCPB spec, and wires in CI/CD- Reusable GitHub Actions workflow: Full CI/CD pipeline for MCPB packaging with build, test, validate, package, and release steps
- Composite GitHub Action: Marketplace-published action for validate, package, checksum, and upload steps within an existing workflow
Installation
As a Claude Code Plugin
Add this repository as a plugin dependency in your Claude Code project, then use /mcpb in any MCP server project.
As a GitHub Actions Reusable Workflow
Reference the reusable workflow at the job level in your caller workflow:
name: Package MCP Bundle
on:
push:
tags: ['v*']
jobs:
package:
uses: zircote/mcp-bundle/.github/workflows/mcp-bundle.yml@v1
with:
source-files: "src/**"
As a GitHub Actions Composite Action (Marketplace)
Reference the action at the step level within an existing job:
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/setup-node@v6
with:
node-version: '20'
- run: npm ci && npm run build && npm test
- uses: zircote/mcp-bundle@v1
Reusable Workflow vs. Composite Action
| Feature | Reusable Workflow | Composite Action |
|---------|-------------------|------------------|
| Usage | uses: at job level | uses: at step level |
| Checkout & setup | Handled automatically | You handle in prior steps |
| Build & test | Configurable via inputs | You handle in prior steps |
| File selection | Via source-files, config-files, additional-artifacts inputs | Bundles working directory; use .mcpbignore to exclude |
| Manifest validation | Full (11 checks) | Full (11 checks) |
| Bundle packaging | Yes | Yes |
| SHA-256 checksum | Yes | Yes |
| Artifact upload | Yes | Yes |
| Release attachment | Yes | Yes |
| Best for | Standalone CI/CD pipeline | Integration into existing workflows |
/mcpb Skill Usage
Run /mcpb in a project directory containing an MCP server. The skill will:
- Detect the MCP server implementation (Node.js, Python, UV, or binary)
- Generate a valid
manifest.jsonfollowing the MANIFEST.md spec - Create the bundle directory structure
- Validate the manifest against schema rules
- Wire in a CI/CD caller workflow that invokes the reusable packaging workflow
Detection Signals
| Language | Detection Criteria |
|----------|-------------------|
| Node.js | @modelcontextprotocol/sdk in dependencies, StdioServerTransport usage |
| Python | mcp package imports, stdio_server() usage, pyproject.toml with MCP deps |
| Python UV | pyproject.toml with mcp dep, no server/lib/ or server/venv/ |
| Binary | Compiled server executables, Cargo.toml/go.mod with MCP dependencies |
Reusable Workflow Reference
Inputs
| Input | Type | Required | Default | Description |
|-------|------|----------|---------|-------------|
| source-files | string | no | src/** | Glob pattern(s) for source files (comma-separated). Fails if no files match — ensure patterns match your project layout |
| manifest-path | string | no | manifest.json | Path to manifest.json |
| config-files | string | no | "" | Glob pattern(s) for config files to include |
| additional-artifacts | string | no | "" | Glob pattern(s) for extra files to bundle |
| node-version | string | no | "20" | Node.js version for build environment |
| build-command | string | no | npm run build | Shell command via bash -c before packaging. Arbitrary code execution — never set from untrusted input |
| test-command | string | no | npm test | Shell command via bash -c before packaging (empty to skip). Arbitrary code execution |
| bundle-name | string | no | "" | Override bundle output filename |
| upload-artifact | boolean | no | true | Upload bundle as GitHub Actions artifact |
| create-release-asset | boolean | no | false | Attach bundle to GitHub Release (tag pushes only) |
| mcpb-version | string | no | latest | Version of mcpb toolchain |
| runs-on | string | no | ubuntu-latest | Runner label for the packaging job |
Outputs
| Output | Description |
|--------|-------------|
| bundle-path | Path to the generated .mcpb bundle file |
| bundle-sha256 | SHA-256 checksum of the bundle |
| manifest-valid | Whether manifest validation passed (true/false) |
Composite Action Reference
The composite action bundles the entire working directory (you handle checkout, build, and file selection in prior steps). Use .mcpbignore to exclude files.
Inputs
| Input | Type | Required | Default | Description |
|-------|------|----------|---------|-------------|
| manifest-path | string | no | manifest.json | Path to manifest.json |
| bundle-name | string | no | "" | Override bundle output filename |
| upload-artifact | string | no | "true" | Upload bundle as GitHub Actions artifact |
| create-release-asset | string | no | "false" | Attach bundle to GitHub Release (tag pushes only) |
| mcpb-version | string | no | latest | Version of mcpb toolchain |
Outputs
| Output | Description |
|--------|-------------|
| bundle-path | Path to the generated .mcpb bundle file |
| bundle-sha256 | SHA-256 checksum of the bundle |
| manifest-valid | Whether manifest validation passed (true/false) |
Manifest Validation Checks
Both the reusable workflow and composite action perform these 11 validation checks:
- All required fields present (
manifest_version,name,version,description,author.name,server.type,server.entry_point) server.typeis one of:node,python,binary,uvversionis valid semver- UV server type requires
manifest_version: "0.4" compatibility.platformsvalues are valid (darwin,win32,linux)server.entry_pointfile exists (warning if missing, expected when build produces it)user_configfield types are valid (string,number,boolean,directory,file)- All
${user_config.*}variable references have matchinguser_configentries - No duplicate tool names in
toolsarray - Each tool entry has both
nameanddescription - JSON is well-formed and parseable
Example Caller Workflows
See the examples/ directory for complete caller workflow files:
minimal-caller.yml— bare minimumstandard-caller.yml— with config files and Node.js 20advanced-caller.yml— with release assets and custom buildbinary-caller.yml— pre-compiled binary server packaging
Bundle Structure
Generated bundles follow the MCPB spec. Structure varies by server type:
bundle.mcpb (ZIP)
├── manifest.json # Required
├── server/
│ └── index.js # Node.js entry point
│ main.py # Python entry point
│ <binary> # Binary entry point
├── node_modules/ # Node.js only
├── package.json # Node.js only (optional)
├── pyproject.toml # UV runtime only
├── requirements.txt # Python only (optional)
├── icon.png # Optional
└── .mcpbignore # Exclusion rules
Testing
Run the test suite:
./tests/test-manifest-validation.sh
The test suite covers:
- Manifest validation: required fields, semver, server types, UV version constraint, platforms, config types, variable substitution refs, duplicate tools
- JSON structure validation for all fixtures
- Workflow and action YAML structure verification
- Glob pattern sanitization and shell metacharacter rejection
- Bundle filename sanitization (path-traversal and empty-name guards)
- Bundle structure validation (manifest.json at root, entry_point presence)
.mcpbignorepattern matching: basename, path-relative, directory, negation handlingcopy_glob()fail-fast behavior and zero-match detection- Security audit: GH_TOKEN sourcing, bash -c vs eval, VERSION/BNAME sanitization
- Skill file structure and content completeness
- Example workflow presence and references
.mcpbignore
Create a .mcpbignore file in your repository root to exclude files from the bundle. Format is similar to .gitignore:
# Comments start with #
*.log # basename: matches *.log at any depth
dist/debug.log # path-relative: only dist/debug.log
tests/ # directory: removes tests/ anywhere
__pycache__/ # directory: removes all __pycache__ dirs
- Blank lines and lines starting with
#are ignored - Patterns ending with
/match directories anywhere in the bundle (e.g.__pycache__/) - Patterns containing
/(not trailing) match path-relative files (e.g.dist/debug.log) - All other patterns match by filename at any depth (e.g.
*.log) - Negation patterns (
!pattern) are not supported and are skipped with a warning
Security Considerations
Note: The reusable workflow uses
bash -cto execute user-providedbuild-commandandtest-commandinputs. These values are passed via environment variables (not interpolated directly into shell), so they are not subject to YAML injection. However, they come fromworkflow_callinputs (set by the calling workflow author), so avoid passing untrusted values through these inputs.
License
MIT
Related Skills
Agent-Reach
91.6kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.4kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
CowAgent
47.2kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Scrapling
85.8k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
