api-to-typemcp
Use when turning supplied API sources into a safe TypeMCP project.
Rank
62
Safety
84
Downloads
1.0k
Updated
Oct 11, 2026
Version
0.2.6
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1K downloadsadoption · observed Oct 11, 2026
- Latest release
- 0.2.6release · observed Aug 13, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17dm9vz4bb1bn0gnwk6bprry98b5a29:api-to-typemcp- Install using `clawhub skill install s17dm9vz4bb1bn0gnwk6bprry98b5a29:api-to-typemcp` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/sjungwon03/api-to-typemcp before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-sjungwon03-api-to-typemcp/snapshot"
Run-check
$0.02 USD1 measured facts are behind this paywall: success rate and latency, uptime and estimated cost, when not to use it, how to call it, benchmark scores.
Agents pay $0.02 in USDC. A card payment is $0.50, the smallest a card allows.
Documentation
CLAWHUB
160,000 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: api-to-typemcp
description: Use when turning supplied API sources into a safe TypeMCP project.
version: 0.2.6
category: integration
license: MIT
metadata:
hermes:
tags: [mcp, api, openapi, swagger, code-generation, type-mcp]
related_skills: []
openclaw:
requires:
bins: [python3, node, npm]
envVars:
- name: TYPE_MCP_APPROVAL_STATE_DIR
required: false
description: Isolated directory for single-use generation approvals.
- name: TYPE_MCP_BASE_URL
required: false
description: Local test upstream used only by contained verification.
---
# API to TypeMCP
## Overview
This released skill is a complete, bundled generator delivery unit. Its **bundled skill engine** is in `scripts/`, its controlled TypeScript output templates are in `templates/`, and its public TypeMCP runtime constraints are in [references/type-mcp-runtime.md](references/type-mcp-runtime.md).
Generated projects use the current published `@theorvane/[email protected]` release line and only its public package exports; they never copy TypeMCP source or use local, `file:`, `git:`, `link:`, or private runtime APIs. The npm registry `gitHead` and GitHub Release `v0.3.2` both resolve to `e75bcf6a81ef4df57301b6154a0088845020886f`.
## When to use
Use this skill with a **supplied local** OpenAPI 3.x / Swagger 2.0 JSON/YAML file, supplied Swagger UI HTML, or supplied Markdown/HTML API reference. Do not use it to crawl a bare origin, infer undocumented operations, make mutating calls by default, or publish without explicit final confirmation.
## Execution permissions and containment boundary
The engine reads only the user-supplied source and files bundled with this skill. It writes only the caller-created output directory and the optional `TYPE_MCP_APPROVAL_STATE_DIR`; it never modifies an upstream API or publishes a repository without the separate explicit gates below.
The engine invokes `python3`. Optional generated-project verification additionally invokes `npm` and `node`, uses a fresh temporary workspace, passes a credential-scrubbed environment, disables inherited npm proxy settings and lifecycle scripts, and installs exactly the generated `package-lock.json` graph with `npm ci`. That install requires outbound access to the npm registry; the generator itself performs no network fetch or crawling, and the smoke test targets only a caller-provided local test upstream.
This verifier is **process containment**, not a claim of kernel or network isolation. Run it in a container, VM, or an equivalent host sandbox when the generated project or its dependency installation is untrusted.
## Bundled engine workflow
Run the engine through its installed skill-relative path. Set `SKILL_DIR` to the directory containing this `SKILL.md`; create a **controlled temporary output directory** yourself and keep it empty.
```bash
SKILL_DIR="/absolute/path/to/api-to-typemcp"
SOURCE="/absolute/path/to/supplied-openapi.json"
OUTPUT="$(_meta.json
{
"ownerId": "kn701ftcm7pjm5537hh2jnv7y18b5q10",
"slug": "api-to-typemcp",
"version": "0.2.6",
"publishedAt": 1786604975571
}references/agent-mcp-installation.md
# Agent MCP Installation Reference **Status:** implementation contract **Retrieved:** 2026-07-28 `api-to-typemcp` produces local stdio MCP projects. Project-only generation is the default. Only after contained generated-project verification may the skill offer agent installation. Detection is read-only; installation requires selected targets, a displayed secret-free plan, and a separate final confirmation. ## Global safety contract - The installer never reads `.env`, resolves credentials, or writes secret values into an agent config, plan, log, backup, or portable export. It displays environment-variable names only. - `generate` never scans or edits agent configuration. - Unknown, malformed, symlinked, fingerprint-changed, or unsupported targets fail closed. - Portable export does not modify an agent configuration. It writes a secret-free standard `mcpServers` snippet under generated-project `agent-install/`. - Per-target failure never implies another target is installed; a changed target has a same-directory backup and target-local rollback. - Protected writes remain fail-closed under `TYPE_MCP_ALLOW_PROTECTED_OPERATIONS`. ## hermes **Official reference:** https://hermes-agent.nousresearch.com/docs/user-guide/features/mcp **Retrieved:** 2026-07-29 Native registration uses only the documented `hermes mcp add <name> --command node --args <absolute-entry>` CLI path. The reviewed plan records the CLI-managed candidate path for operator visibility but the installer never reads or edits it directly. After registration, it runs `hermes mcp test <name>`; any non-zero result triggers `hermes mcp remove <name>` as compensating rollback. Hermes CLI currently exposes no cwd flag, so the generated absolute `dist/index.js` entrypoint is used and the plan reports the canonical project cwd for review. Environment variable values are never read or passed; users provide required values through their Hermes execution environment. ## claude-code **Official reference:** https://docs.anthropic.com/en/docs/claude-code/mcp **Retrieved:** 2026-07-29 Native registration uses the documented stdio form `claude mcp add --transport stdio <name> -- node <absolute-entry>`, where `--` separates Claude Code options from the server command. The installer never reads or edits Claude settings directly. It verifies registration using `claude mcp list` and requires the named server in successful output; a failed or absent discovery triggers `claude mcp remove <name>` as compensating rollback. Claude Code’s documented add form has no cwd argument, so the generated absolute entrypoint is used and the canonical project cwd remains plan-visible only. Environment variable values are never read or passed; users provide required values through their Claude Code execution environment. ## codex **Official reference:** https://developers.openai.com/codex/cli/reference **Retrieved:** 2026-07-28 Preferred path: `codex mcp add`, `codex mcp get`, and `codex mcp list`. Native entries u
references/type-mcp-runtime.md
# TypeMCP Runtime Contract Generated projects use the reviewed public npm package on the current 0.3.2 release line: ```json "@theorvane/type-mcp": "0.3.2" ``` `@theorvane/[email protected]` is published with npm registry `gitHead` and GitHub Release `v0.3.2` both resolving to `e75bcf6a81ef4df57301b6154a0088845020886f`. ## Allowed public API The generator's default standard ESM path uses standard decorators from the public ESM/NodeNext entrypoint: ```ts import { McpServer, McpTool } from "@theorvane/type-mcp"; ``` Generated TypeScript uses only these public exports: - `@McpServer` - `@McpTool` - `createMcpServer` - `startStdioServer` - `zod` - an explicit `InstanceResolver` `createMcpServer` and `startStdioServer` are asynchronous and must be awaited. Standard decorators use TC39 semantics: generated `tsconfig.json` must not enable legacy `experimentalDecorators` or `emitDecoratorMetadata`. `@McpTool` requires an `input` Zod object. Generated code pins Zod v4 (`^4.4.3`) because that is the compatible public runtime contract for `@theorvane/[email protected]`. ## Legacy decorator compatibility Standard and legacy decorators use distinct entrypoints and distinct decorator semantics. Legacy decorators are an opt-in public entrypoint for external CommonJS/Node16 projects that intentionally use TypeScript's legacy decorator mode; those projects must enable `experimentalDecorators` and import the decorators only from: ```ts import { McpServer, McpTool } from "@theorvane/type-mcp/legacy"; ``` Do not mix this entrypoint with the standard ESM/NodeNext imports. The generator does not copy TypeMCP runtime source and must remain on its default standard ESM path; do not change its templates to legacy decorators or CommonJS. ## Prohibited runtime boundaries Never generate or publish any of the following: - copied TypeMCP source code; - `file:`, `git:`, `link:`, or `portal:` dependencies; - imports from private, undocumented, or unavailable TypeMCP APIs; - local TypeMCP checkouts as a generated-project dependency. Before generated lifecycle scripts run, contained verification inspects dependency metadata and the generated `package-lock.json`, then runs `npm ci --ignore-scripts` in a fresh isolated workspace with inherited npm proxy configuration disabled. It then typechecks, tests, builds, and executes a local stdio smoke test against a mock upstream. Use a host container/VM/sandbox when the dependency graph is untrusted.
skill-card.md
## Description: Use when turning supplied API sources into a safe TypeMCP project. This skill is ready for commercial/non-commercial use. ## Publisher: [sjungwon03](https://clawhub.ai/user/sjungwon03) ### License/Terms of Use: MIT-0 ## Use Case: Developers and engineers use this skill to convert supplied local OpenAPI, Swagger UI, or Markdown/HTML API references into a reviewed TypeMCP stdio MCP project. It is intended for project generation first, with optional agent installation only after verification and explicit confirmation. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: A replace-generation path can overwrite files outside the chosen output folder. Mitigation: Generate into a newly created empty directory, avoid --replace on directories that were not created and inspected for this run, and review paths before generation. Risk: Agent installation can modify persistent MCP client configuration. Mitigation: Prefer project-only generation, review the secret-free installation plan, and require explicit confirmation before applying any agent configuration changes. Risk: Generated project verification installs npm dependencies and may be untrusted. Mitigation: Run npm verification in a container, VM, or equivalent host sandbox for untrusted inputs. ## Reference(s): - [ClawHub skill page](https://clawhub.ai/sjungwon03/skills/api-to-typemcp) - [TypeMCP Runtime Contract](references/type-mcp-runtime.md) - [Agent MCP Installation Reference](references/agent-mcp-installation.md) - [Hermes MCP documentation](https://hermes-agent.nousresearch.com/docs/user-guide/features/mcp) - [Claude Code MCP documentation](https://docs.anthropic.com/en/docs/claude-code/mcp) - [Codex CLI MCP reference](https://developers.openai.com/codex/cli/reference) - [Cursor MCP documentation](https://cursor.com/docs/mcp) - [VS Code MCP servers documentation](https://code.visualstudio.com/docs/agent-customization/mcp-servers) ## Skill Output: **Output Type(s):** [text, markdown, code, shell commands, configuration, guidance] **Output Format:** [Markdown guidance plus generated TypeScript project files and JSON/TOML MCP configuration snippets] **Output Parameters:** [1D] **Other Properties Related to Output:** [Generated projects use a pinned TypeMCP runtime line and may include optional agent installation plans or portable MCP server exports.] ## Skill Version(s): 0.2.6 (source: server release metadata and SKILL.md frontmatter) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/sjungwon03/skills/api-to-typemcp",
"sourceUrl": "https://clawhub.ai/sjungwon03/skills/api-to-typemcp",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T16:10:22.180Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-sjungwon03-api-to-typemcp/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-sjungwon03-api-to-typemcp/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T16:10:22.180Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1K downloads",
"href": "https://clawhub.ai/sjungwon03/api-to-typemcp",
"sourceUrl": "https://clawhub.ai/sjungwon03/api-to-typemcp",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T16:10:22.180Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.2.6",
"href": "https://clawhub.ai/sjungwon03/api-to-typemcp",
"sourceUrl": "https://clawhub.ai/sjungwon03/api-to-typemcp",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-13T07:09:35.571Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-sjungwon03-api-to-typemcp/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-sjungwon03-api-to-typemcp/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.2.6",
"description": "- Bumped version to 0.2.6. - Documentation updates in SKILL.md. - Removed unused file skill-card.md. - Minor changes and cleanup to scripts and test files.",
"href": "https://clawhub.ai/sjungwon03/api-to-typemcp",
"sourceUrl": "https://clawhub.ai/sjungwon03/api-to-typemcp",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-13T07:09:35.571Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
