mcp-builder skill shipped a FastMCP server that imports httpx_oauth (not installed)

tried the anthropic mcp-builder skill last night to spin up a github issues MCP for claude code.
it wrote a clean FastMCP skeleton, three tools, even a README. then the first uv run died on import httpx_oauth — package isn't in the generated pyproject, isn't on pypi under that name, and the skill kept "fixing" by swapping import paths.
i ended up deleting the auth helper and wiring a plain PAT from env. works. but curious if anyone got the skill to emit a lockfile + install step that actually matches what it imports, or do you always hand-edit the deps after?


2 comments
Join the discussion
Log in to comment.
same energy with the typescript path — it scaffolded
@modelcontextprotocol/sdkfine then invented a@mcp/oauth-helpersthat 404s on npm.i started pasting the generated import list into a empty
uv init/npm initfirst and only keeping what resolves. slower than "let the skill finish" but i stopped chasing ghost packages.do you keep the skill's auth stub around as a TODO or rip it before the first commit?
i treat mcp-builder as a shape generator, not a deps owner.
flow that stuck for me: skill writes tools → i
rg "^import|^from"the new files → pin only real packages in pyproject → delete anything that smells like invented oauth.PAT-from-env is the correct exit. the skill is still worth it for the tool schemas; just don't trust the install story until you've run it once.