MCP (Model Context Protocol) Ecosystem Explained: The Three Core Primitives of Tool, Resource, and Prompt
What Is MCP?
MCP (Model Context Protocol) is an open-source protocol introduced by Anthropic that defines a standard interface between LLMs and external tools/data sources. It enables AI clients such as Claude Code to securely access external resources such as local files, databases, and APIs.
Core Concepts
┌──────────────┐ MCP Protocol ┌──────────────┐
│ MCP Client │ ◄──────────────────► │ MCP Server │
│ (Claude Code)│ JSON-RPC 2.0 │ (tool/data) │
└──────────────┘ └──────────────┘
Three Major Primitives
| Primitive | Purpose | Example |
|---|---|---|
| Tool | Allows the LLM to perform operations | Query databases, send HTTP requests |
| Resource | Exposes data to the LLM | File contents, API responses |
| Prompt | Predefined prompt templates | Code review templates, translation templates |
Tool
Tool enables LLMs to perform actions, not just generate text.
Built-in Commonly Used MCP Servers
# File System Access
npx @anthropic-ai/mcp-server-filesystem /path/to/allowed/dir
# GitHub Integration
npx @anthropic-ai/mcp-server-github
# PostgreSQL Queries
npx @anthropic-ai/mcp-server-postgres
# Brave Search
npx @anthropic-ai/mcp-server-brave-search
# Puppeteer Browser
npx @anthropic-ai/mcp-server-puppeteer
Configure Claude Code to Use MCP
Edit ~/.claude.json:
{
"mcpServers": {
"filesystem": {
"command": "npx",
"args": ["@anthropic-ai/mcp-server-filesystem", "/Users/me/projects"],
"env": {}
},
"github": {
"command": "npx",
"args": ["@anthropic-ai/mcp-server-github"],
"env": {
"GITHUB_TOKEN": "ghp_xxx"
}
}
}
}
After configuring, restart Claude Code and enter /mcp to view connected servers.
Resource
Resource allows LLMs to read structured data without users pasting content.
Typical Scenarios
- Database Schema: Let the LLM understand the table structure and automatically generate SQL
- API Documentation: Automatically read the OpenAPI spec and generate correct API calls
- Project Structure: Expose the project file tree so the LLM can understand the codebase layout
{
"mcpServers": {
"postgres": {
"command": "npx",
"args": ["@anthropic-ai/mcp-server-postgres", "postgresql://localhost/mydb"]
}
}
}
Prompt (Prompt Templates)
Prompt provides reusable prompt templates to ensure consistency.
{
"mcpServers": {
"review-templates": {
"command": "npx",
"args": ["@anthropic-ai/mcp-server-prompt", "--dir", "~/.claude/prompts"]
}
}
}
Place .md files under ~/.claude/prompts/ and they can be invoked through MCP.
Hands-On: Building a Custom MCP Server
# my_mcp_server.py
from mcp.server import Server, NotificationOptions
from mcp.server.models import InitializationCapabilities
import mcp.server.stdio
import mcp.types as types
server = Server("my-tools")
@server.list_tools()
async def handle_list_tools() -> list[types.Tool]:
return [
types.Tool(
name="get_weather",
description="Get the weather for a specified city",
inputSchema={
"type": "object",
"properties": {
"city": {"type": "string", "description": "City name"}
},
"required": ["city"]
}
)
]
@server.call_tool()
async def handle_call_tool(name: str, arguments: dict):
if name == "get_weather":
city = arguments["city"]
# Actually call the weather API
return [types.TextContent(type="text", text=f"{city} Weather: Sunny 25°C")]
async def run():
async with mcp.server.stdio.stdio_server() as (read_stream, write_stream):
await server.run(read_stream, write_stream,
InitializationCapabilities(
sampling={},
experimental={},
))
if __name__ == "__main__":
import asyncio
asyncio.run(run())
Register it in ~/.claude.json:
{
"mcpServers": {
"my-tools": {
"command": "python",
"args": ["/path/to/my_mcp_server.py"]
}
}
}
Security Considerations
MCP Server can access the file system and network, so caution is required:
- Principle of least privilege: the filesystem server should expose only the necessary directories
- Environment variable isolation: pass sensitive credentials via env, and do not write them to configuration files
- Audit logs: regularly review MCP Server access records
- Do not expose the
/root directory: limit the filesystem server's access scope
Recommended Reading
More in Learn
- Complete LangChain Tutorial 2026: Building Enterprise-Grade LLM Applications from Scratch
- MemoryHub v2.0 System Architecture In-Depth Analysis: From Capture Daemon to MCP Real-Time Memory Capture
- May 2026 LLM API Pricing Landscape: Complete Comparison of DeepSeek, Qwen, GLM, Kimi, MiniMax, and Doubao
- Cross-Channel Memory Hub: A Full Record of the Memory System Architecture Design for OpenClaw Agent