Complete AI Training

Skill · Mcp

Mcp integration

Generates and reviews MCP server configuration for plugins, covering stdio, SSE, HTTP, and WebSocket setups, tool naming, permissions, security, and lifecycle. Use when adding or integrating an MCP server, writing .mcp.json or plugin.json config, or checking an MCP configuration for hardcoded secrets and insecure URLs.

Complete AI SkillsLicense: MITAdded Sep 29, 2026

How to use it

  1. Start your plan and connect your AI once
  2. Ask for the task in your own words, or say it directly:
Use the Mcp integration skill to help me with this.

Without a connection: copy the SKILL.md below into your AI's project instructions.

SKILL.md

MCP Server Configuration

Helps plugin developers configure Model Context Protocol servers in their plugins by generating JSON configuration, explaining setup methods, and advising on authentication, naming, security, and lifecycle. For developers integrating external tools into a plugin; it does not implement servers, write plugin code beyond configuration, or handle deployment.

When to use

  • Adding or integrating an MCP server into a plugin.
  • Choosing between stdio, SSE, HTTP, or WebSocket for a given use case.
  • Writing or editing a .mcp.json or plugin.json configuration block.
  • Setting up environment variable expansion for tokens and keys.
  • Pre-allowing MCP tools in command frontmatter or building an allowed-tools list.
  • Reviewing an existing MCP configuration for hardcoded secrets, non-HTTPS/WSS URLs, or undocumented environment variables.
  • Verifying that configured servers are registered.

Workflows

Guide MCP server configuration

Inputs: Interview once to determine the server type (stdio, SSE, HTTP, or WebSocket), the plugin root path, any required environment variables, and the authentication method. Save the chosen server type and connection details so future conversations pick up without re-asking.

  1. Confirm the server type, plugin root path, required environment variables, and authentication method.
  2. Select the target file: .mcp.json or the plugin.json configuration block.
  3. Generate the configuration block for the chosen server type with environment variable expansion for all secrets.
  4. Show the snippet and state where it belongs relative to the plugin root.
  5. Record the server type and connection details for later sessions.

Check: The snippet parses as valid JSON, every token or key is an environment variable reference, and the file location matches the plugin root the user gave. Output: A JSON configuration block plus a one-line note on its file location.

Explain MCP server types and use cases

Inputs: The user's use case: local, hosted, stateless, or streaming.

  1. Describe the four types: stdio for local processes, SSE for cloud services with OAuth, HTTP for token-based REST APIs, WebSocket for real-time connections.
  2. Provide a concrete JSON example for each type.
  3. Recommend a type based on the use case and explain why it beats the alternatives.

Check: Each example is valid JSON and matches its stated type. Output: Descriptions of the four types, one JSON example each, and a recommendation with reasoning.

Advise on MCP tool naming and permissions

Inputs: The server name and the tool set the user wants to allow.

  1. Explain the automatic prefix format mcp__plugin_<name>_<server>__<tool>.
  2. Explain how to pre-allow specific tools in command frontmatter.
  3. Recommend allowing exact tool names rather than wildcards.
  4. If asked, generate an allowed-tools list for the given server and tool set.

Check: Every generated tool name follows the prefix format exactly. Output: An explanation of the prefix and frontmatter, plus an allowed-tools list when requested.

Review security and lifecycle best practices

Inputs: The proposed MCP configuration.

  1. Check for hardcoded tokens and replace them with environment variable references.
  2. Verify that URLs use HTTPS or WSS.
  3. Remind the user to document required environment variables.
  4. Describe the automatic startup and connection lifecycle.
  5. Suggest using the /mcp command to verify servers are registered after configuration.

Check: No hardcoded secrets remain, all URLs are HTTPS or WSS, and required environment variables are documented. Output: A list of findings with corrected configuration snippets where needed.

Tools and data

  • Use the /mcp command when available to verify servers are registered after configuration.

Guardrails

  • Only generate configuration snippets inside .mcp.json or plugin.json; never write the MCP server code itself.
  • Never produce configuration with hardcoded secrets—require environment variable references for tokens and keys.
  • Do not deploy, test, or run MCP servers; provide instructions only.

Getting started

Ask the user three things: the type of MCP server they want to integrate (stdio, SSE, HTTP, or WebSocket), the plugin root directory path, and any environment variables the server needs. Save these answers so you never ask again in future sessions.

Credits

Adapted from an open-source original (MIT): https://www.aitmpl.com/component/skills/development/mcp-integration