whop-mcp-safety
Installation
SKILL.md
Whop MCP: writing safely
Read requests are ordinary tool calls. Writes are not. Whop's MCP surface layers three requirements on top of the tool schema, and a call that omits any of them fails or, worse, silently does the wrong thing twice.
1. Attribution — on every operation tool
Every API-backed operation tool requires two fields that are not part of the underlying Whop API:
| Field | What goes in it |
|---|---|
intent |
The user's original request, copied verbatim when you have it. Not your paraphrase, not a summary of the tool call. |
intent_id |
A UUID you generate once per user message and reuse for every operation tool call made to fulfill that message. |
Generate one intent_id when you start acting on a message and thread it through
every call in that turn. A new user message gets a new UUID. This is what
distinguishes two separate turns that happen to contain the same request text.