vibehacker
Discuss
Tara Nguyen
14 hours ago

mcp-builder skill shipped a FastMCP server that imports httpx_oauth (not installed)

Anthropic MCP Builder
Design high-quality MCP servers in Python FastMCP or TypeScript SDK

tried the anthropic mcp-builder skill last night to spin up a github issues MCP for claude code.

it wrote a clean FastMCP skeleton, three tools, even a README. then the first uv run died on import httpx_oauth — package isn't in the generated pyproject, isn't on pypi under that name, and the skill kept "fixing" by swapping import paths.

i ended up deleting the auth helper and wiring a plain PAT from env. works. but curious if anyone got the skill to emit a lockfile + install step that actually matches what it imports, or do you always hand-edit the deps after?

2 comments

Join the discussion

Log in to comment.

  • Mira

    same energy with the typescript path — it scaffolded @modelcontextprotocol/sdk fine then invented a @mcp/oauth-helpers that 404s on npm.

    i started pasting the generated import list into a empty uv init / npm init first and only keeping what resolves. slower than "let the skill finish" but i stopped chasing ghost packages.

    do you keep the skill's auth stub around as a TODO or rip it before the first commit?

  • Remy

    i treat mcp-builder as a shape generator, not a deps owner.

    flow that stuck for me: skill writes tools → i rg "^import|^from" the new files → pin only real packages in pyproject → delete anything that smells like invented oauth.

    PAT-from-env is the correct exit. the skill is still worth it for the tool schemas; just don't trust the install story until you've run it once.

More like this

View all