← Back to Skills Marketplace
tangweigang-jpg

Mcp Python Sdk

by Tang Weigang · GitHub ↗ · v0.1.0 · MIT-0
cross-platform ⚠ suspicious
65
Downloads
0
Stars
0
Active Installs
1
Versions
Install in OpenClaw
/install mcp-python-sdk
Description
MCP Python SDK:Anthropic 主导的 Model Context Protocol 参考实现。2 server 层 + 3 transport + 3 原语 + 4 协议版本 + 50 条约束。 MCP Python SDK: reference Python implementation o...
Usage Guidance
This package is inconsistent: it presents as an MCP SDK but includes a compiled finance blueprint that tells the agent to run Python checks, install recipes, and rely on ZVT and environment paths that aren't declared. Before installing or running it, (1) verify you actually intended a finance/backtest blueprint rather than an MCP SDK, (2) open and read references/seed.yaml and human_summary.md in full to see the exact commands and preconditions, (3) do not let an agent run install or shell commands from this skill in a production environment — run them manually in a sandbox first, (4) confirm any required env vars (e.g., ZVT_HOME, API tokens) and package installs (zvt, pywin32, AnyIO, Starlette) and only provide secrets that are strictly necessary, and (5) ask the author to correct the skill metadata (declare required binaries/env, or remove unrelated finance content) — that clarification would materially reduce the risk and could change the assessment to benign.
Capability Analysis
Type: OpenClaw Skill Name: mcp-python-sdk Version: 0.1.0 The skill bundle is a comprehensive reference implementation and operational guide for the Model Context Protocol (MCP) and the ZVT quant trading library. The files (SKILL.md, seed.yaml) contain detailed instructions for an AI agent to manage data collection, factor computation, and backtesting. Security-wise, the bundle includes proactive constraints against common vulnerabilities, such as DNS-rebinding protection (mcp-C-003) and preventing internal data leakage in error responses (mcp-C-029). While the preconditions in references/seed.yaml perform file system checks (e.g., PC-04 touching ~/.zvt), these actions are strictly aligned with the stated purpose of initializing local financial databases. No evidence of malicious intent, exfiltration, or unauthorized remote execution was found.
Capability Tags
cryptocan-make-purchasesrequires-oauth-tokenrequires-sensitive-credentials
Capability Assessment
Purpose & Capability
Name/description present an MCP Python SDK reference implementation, but metadata and included files (human_summary.md and references/seed.yaml) are a compiled finance blueprint (finance-bp-140) describing ZVT backtests, Doraemon persona, and finance-specific tooling. This mismatch between declared purpose and actual content is incoherent.
Instruction Scope
SKILL.md and seed.yaml instruct the host agent to reload seed.yaml, run precondition checks (python3 -c 'import zvt' etc.), execute install triggers, and read LATEST.yaml/LATEST.jsonl — actions that touch the filesystem, run shell/python commands, and may trigger package installs. Those runtime actions go beyond a simple documentation skill and reference finance-specific runtime checks not declared in the skill header.
Install Mechanism
There is no install spec (instruction-only), which minimizes delivery-time risk; however seed.yaml includes install_trigger and host_adapter.install_recipes[] references meaning the agent is expected to run installs on the host at runtime. Because no explicit install recipe is packaged, the actual install behavior depends on agent implementation and could lead to unexpected package installs.
Credentials
The skill declares no required env vars or config paths, yet seed.yaml and preconditions reference environment state (ZVT_HOME), python/pip availability, and services (eastmoney, OAuth flows in intent_router). Credentials or environment requirements are not declared, which is disproportionate and hides needed permissions/resources.
Persistence & Privilege
always is false and the skill is user-invocable; it does not request persistent/always-on privileges or modify other skills. Autonomous invocation is allowed by default and not an added flag here.
How to Use
  1. Make sure OpenClaw is installed (local or Docker)
  2. Run the install command in chat: /install mcp-python-sdk
  3. After installation, invoke the skill by name or use /mcp-python-sdk
  4. Provide required inputs per the skill's parameter spec and get structured output
Version History
v0.1.0
MCP Python SDK skill — 50 constraints / 1 fatal. 4 protocol versions, 3 transports, 3 primitives.
Metadata
Slug mcp-python-sdk
Version 0.1.0
License MIT-0
All-time Installs 0
Active Installs 0
Total Versions 1
Frequently Asked Questions

What is Mcp Python Sdk?

MCP Python SDK:Anthropic 主导的 Model Context Protocol 参考实现。2 server 层 + 3 transport + 3 原语 + 4 协议版本 + 50 条约束。 MCP Python SDK: reference Python implementation o... It is an AI Agent Skill for Claude Code / OpenClaw, with 65 downloads so far.

How do I install Mcp Python Sdk?

Run "/install mcp-python-sdk" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.

Is Mcp Python Sdk free?

Yes, Mcp Python Sdk is completely free, licensed under MIT-0. You can download, install and use it at no cost.

Which platforms does Mcp Python Sdk support?

Mcp Python Sdk is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).

Who created Mcp Python Sdk?

It is built and maintained by Tang Weigang (@tangweigang-jpg); the current version is v0.1.0.

💬 Comments