Home/Blog/How to Write an MCP Server Tool Spec from a Capability List
Blog

How to Write an MCP Server Tool Spec from a Capability List

P
promptstudio
How to Write an MCP Server Tool Spec from a Capability List

MCP specs invent https://api.example.com and a second tool. The capability list named extract_ticket with title and priority. TRANSPORT UNKNOWN.

The matching generator is the MCP Server Tool Spec from a Capability List (No Invented API Keys or Endpoints) (Mcp Server Tool Spec From A Capability List No Invented Api Keys Or Endpoints) prompt. Browse related cards in the PromptDig library (Browse more prompts). When a filled run survives, share the version you actually use (Share a prompt).

Print the tool lock table first

Write an MCP server tool spec from a capability list. No invented API keys, endpoints, or extra tools. Start by filling Inputs, not by asking the model to remember last week's run. If a field is blank, write NONE or NOT IN INPUTS and leave it blank through Generate. The card is built so the model cannot honestly invent a number, owner, URL, or command that you did not paste.

Paste these fields before you hit run:

Capability list I lock (tool names, fields, descriptions I allow): [Caps]
MCP version I lock (or UNKNOWN): [Version]
Transport I lock (or UNKNOWN): [Transport]
Words I must not use: [Banned]
What I must never invent (API keys, endpoints, extra tools): [Never]
Output format: [Format]
Language for comments: [Lang]
Secrets style I lock (env names only): [Secrets]

That inventory is the honesty ledger. Anything that does not appear there is forbidden in the draft. If you catch yourself adding a nice-to-have after the run, you are no longer using the card. You are ghostwriting. Put the extra fact in Inputs and run again.

Write tools only from the capability list

Generate is numbered on purpose. Do not skip a step because the first paragraph looked done. The early steps exist to stop later prose from smuggling claims.

Walk the Generate list in order:

  1. Honesty ledger: Caps, Version, Transport, Secrets, Lang. Forbidden: invented keys, extra tools, extra endpoints.
  2. Tool lock table: each tool in Caps quoted. Tools not listed stay NOT IN INPUTS.
  3. Spec: tools/list entries only from Caps. Input schemas only from Caps fields. Transport from Transport or TRANSPORT UNKNOWN.
  4. Secrets: env names from Secrets only. Never paste sk- values.
  5. Refuse list: OpenAPI 3 paths, LangChain @tool, DSPy Signature, raw API keys, invented stdio URLs if Transport is UNKNOWN.
  6. Version: quote Version or write VERSION UNKNOWN.
  7. Never: do not add a resources/list tool if Caps omitted it. Do not invent https://api.example.com.
  8. Compliance pass: quote Banned and Never hits. Cut them. Format as Format.

If a step asks for a version lock, quote the version from Inputs in the output. If a step asks for a refuse list, keep the refuse list in the published artifact, not in a sidebar you delete. Reviewers should see what the model was not allowed to do.

Refuse OpenAPI and LangChain dumps

Most failures are the same shape: a missing field gets a confident fill. A conversion rate appears. A Gradle task appears. A flash point appears. A caption appears on a job that asked for slide text only. Your review is to search the draft for numbers, names, and commands, then grep Inputs. No match means cut.

Honor the constraints as hard stops, not vibes:

  • MCP tool spec from Caps only. Not OpenAPI and not LangChain.
  • Never invent API keys, extra tools, or endpoints.
  • Secrets stay env names.
  • No emojis.

When the card says not legal advice, not certification, not an exam dump, or not a caption engine, that sentence belongs at the top of the output. Deleting it to look more finished is how you inherit risk.

Keep secrets as env names only

Finish with the compliance pass the prompt already asks for. Quote the banned-word hits. Cut them. Print character counts when the job has a cap. Print word counts when the job has a budget. List gaps as gaps. Five missing facts are more useful than one smooth paragraph.

Tags on the card (mcp server tool spec, capability list lock, no invented api keys) are a reminder of the job shape, not an invitation to wander into a neighboring cluster. If you need a different surface, open a different PromptDig card rather than stretching this one.

Fill the card, then run

Replace every bracket. Run on ChatGPT, Claude, or Gemini. Read the ledger first, then the artifact. If the model invents a commit, KPI, DOI, PEL, bid, or logo, discard the run. Tighten Inputs. Run again. Share the filled card that survived, not the first draft that sounded done.