MCP Architect

    1

    Designs the boundary between AI hosts, MCP clients and servers: versions, capabilities, tools, authorization, consent.

    $12

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    MCP Architect

    Example session with this skill installed

    Architect the Model Context Protocol (MCP) boundary for our Developer Portal Copilot.

    • Host: DevPortal Copilot (desktop & web), owned by DevEx team (Sarah Chen). Protocol: MCP spec 2024-11-05 over JSON-RPC 2.0.
    • Client A / Server A: catalog-mcp-server (internal, Platform team, Marcus Vance). Transport: local stdio. Exposes tools get_service_metadata (read) and restart_k8s_pod (destructive).
    • Client B / Server B: vendor-diag-mcp (CloudMetrics Inc, external SaaS). Transport: Streamable HTTP/SSE with bearer token. Exposes tool query_telemetry and resource telemetry://alerts/{id}.
    • Tensions:
      1. Platform team wants restart_k8s_pod called autonomously when prompt says 'auto-fix', but Security policy POL-SEC-81 requires explicit out-of-band human consent for destructive actions.
      2. Vendor server advertises sampling capability to call host LLM during synthesis, threatening unbounded recursion and context exhaustion.
      3. Vendor telemetry responses contain prompt-injection payloads in stack traces.
    • Constraints: Resource context budget capped at 8,192 tokens per turn; tool execution timeout 5,000 ms.

    Write the architecture specification under docs/.

    • Read your context and instructions
    • Compiled the mcp architect

    Wrote docs/architecture/mcp-architect/00-overview/mcp-architect-overview.md. Boundary pinned to MCP spec 2024-11-05 with strict external isolation, mandatory POL-SEC-81 human consent, rejection of vendor sampling, and an 8,192-token truncation ceiling.


    skill: mcp-architect


    DevPortal Copilot MCP Interoperability Architecture [MCP-DEVPORTAL-001]

    Summary

    Defines the interoperability boundary between DevPortal Copilot (Host) and two MCP servers: internal catalog-mcp-server (stdio, trusted) and third-party vendor-diag-mcp (HTTP/SSE, untrusted). Pinned to MCP revision 2024-11-05. Three non-negotiable boundaries:

    1. restart_k8s_pod never runs autonomously. Prompts containing "auto-fix" are not authorization; out-of-band operator confirmation is mandatory per POL-SEC-81.
    2. sampling is disabled for the vendor client, blocking third-party recursive model calls and host context depletion.
    3. All vendor telemetry is treated as untrusted passive data, wrapped in inert delimiters so injected instructions cannot reach the planner.

    Contracts and Invariants

    IDInvariantEnforcement
    PA-1Protocol pinned to MCP 2024-11-05Newer or unsupported versions rejected with JSON-RPC -32602
    CE-1restart_k8s_pod requires interactive consentMissing consent yields denied_by_policy, not a retry
    CD-1Client B initializes with capabilities.sampling = nullAny sampling/createMessage returns JSON-RPC -32601
    CB-1Vendor content truncated at 8,192 tokensTruncation sets header X-Content-Truncated: true
    TO-1Tool execution capped at 5,000 msTimer cancellation via notifications/cancelled; late returns dropped

    Alternatives rejected

    OptionWhy it was not takenUnder what evidence it would win
    Autonomous restart on "auto-fix"Violates POL-SEC-81; prompt text can be spoofed or hallucinatedFormal security waiver scoped to dev-only clusters
    Vendor sampling with depth limitHost tokens and API budget spent by external logic without caller visibilityCloudMetrics reimburses token spend and signs a deterministic call-tree SLA
    Direct REST instead of MCPSilos telemetry and catalog into proprietary adapters; loses standard discoveryHost deprecates dynamic tool discovery for static plugins

    Fitness Self-Check

    CriterionProbeResult
    Unbounded AutonomySynthetic "auto-fix pod crashloop" prompt with simulated auto-approvalpass
    Self-Graded EvaluationMock vendor returns success flag alongside an internal error payloadpass
    Prompt-Only ControlAdversarial override injected inside a telemetry stack tracepass

    Limits: probes verify the host client gate and parser, not Kubernetes RBAC outside the MCP client.

    Residual Risk

    HTTP/SSE keepalive drops on the vendor client may leave tool runs unacknowledged if query_telemetry lacks idempotency tokens. Accepted pending CloudMetrics SLA documentation.

    Next steps

    1. DevEx updates the MCP client config to disable capabilities.sampling.
    2. Platform implements the host-side confirmation modal for restart_k8s_pod.
    3. InfoSec signs off on the sanitization delimiter structure before Client B goes to production.

    Connects securely to your tools. The creator never sees your data.

    What you get

    - Define protocol versioning and capability negotiation rules- Map trust boundaries between hosts, clients, and servers- Architect discovery semantics for tools and resources- Establish session, transport, and error handling contracts

    About this skill

    MCP Architect (Model Context Protocol): Full Description

    What it does

    This skill owns interoperability architecture between an AI application host, its MCP clients, and MCP servers. It defines protocol/version boundaries, initialization and negotiated capabilities, primitive ownership, discovery, session/transport behavior, identity and delegated authority, consent, trust, errors, and compatibility. It does not own each tool's business semantics or server/client implementation.

    Use it when

    • Multiple hosts, clients, or servers require a stable interoperability boundary
    • Protocol revisions and initialization/version negotiation need decisions
    • Client/server capability declarations govern optional behavior
    • Tools, resources, and prompts need distinct ownership and discovery semantics
    • List/read/get/call/result contracts, schemas, pagination, and notifications compose
    • Local/remote transports differ in process, session, authentication, or failure behavior

    For example: “Our IDE assistant should talk to our internal ticket system and a vendor's code-scanning server. The vendor's server sometimes returns fields we don't recognise.”

    What you get

    • architecture/mcp-architect/README.md
    • architecture/mcp-architect/00-overview/mcp-architect-overview.md
    • architecture/mcp-architect/verification/fitness-self-check.md

    Plus one page per business module, only where your evidence calls for it: {module}/provider-contract.md, {module}/translation.md, {module}/failure-mapping.md, {module}/credentials.md, {module}/idempotency.md.

    All paths are relative to the output folder you choose.

    What it will not do

    Do not use merely to implement or debug one MCP server/client/tool, wrap an API, design generic agent tools, configure a connector, build MCP UI, or choose an SDK/transport.

    How it works

    1. Pin the protocol revision.
    2. Draw the topology.
    3. Decide what each server owns.
    4. State negotiated capabilities.
    5. Bound session and transport behavior.
    6. Write the deliverable, classify every claim by its evidence, and check it before calling the work done.

    What's in the package

    Instruction-only: no scripts, no network calls, no environment variables.

    • LICENSE.txt
    • SKILL.md
    • agents/openai.yaml
    • assets/output-template-artifact.md
    • assets/output-template-contract.md
    • assets/output-template-domain.md
    • assets/output-template-fitness.md
    • assets/output-template-mechanism.md
    • references/domain-rules.md
    • references/operating-rules.md
    • references/output-contract.md

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 13 days ago

    • Passed all security checks, Safe to install

    Listed13 days ago

    What's inside

    Frequently Asked Questions