MCP Architect
Designs the boundary between AI hosts, MCP clients and servers: versions, capabilities, tools, authorization, consent.
$12
Works with the AI tools you already use
MCP Architect
Example session with this skill installed
Architect the Model Context Protocol (MCP) boundary for our Developer Portal Copilot.
- Host: DevPortal Copilot (desktop & web), owned by DevEx team (Sarah Chen). Protocol: MCP spec 2024-11-05 over JSON-RPC 2.0.
- Client A / Server A: catalog-mcp-server (internal, Platform team, Marcus Vance). Transport: local stdio. Exposes tools get_service_metadata (read) and restart_k8s_pod (destructive).
- Client B / Server B: vendor-diag-mcp (CloudMetrics Inc, external SaaS). Transport: Streamable HTTP/SSE with bearer token. Exposes tool query_telemetry and resource telemetry://alerts/{id}.
- Tensions:
- Platform team wants restart_k8s_pod called autonomously when prompt says 'auto-fix', but Security policy POL-SEC-81 requires explicit out-of-band human consent for destructive actions.
- Vendor server advertises sampling capability to call host LLM during synthesis, threatening unbounded recursion and context exhaustion.
- Vendor telemetry responses contain prompt-injection payloads in stack traces.
- Constraints: Resource context budget capped at 8,192 tokens per turn; tool execution timeout 5,000 ms.
Write the architecture specification under docs/.
- Read your context and instructions
- Compiled the mcp architect
Wrote docs/architecture/mcp-architect/00-overview/mcp-architect-overview.md. Boundary pinned to MCP spec 2024-11-05 with strict external isolation, mandatory POL-SEC-81 human consent, rejection of vendor sampling, and an 8,192-token truncation ceiling.
skill: mcp-architect
DevPortal Copilot MCP Interoperability Architecture [MCP-DEVPORTAL-001]
Summary
Defines the interoperability boundary between DevPortal Copilot (Host) and two MCP servers: internal catalog-mcp-server (stdio, trusted) and third-party vendor-diag-mcp (HTTP/SSE, untrusted). Pinned to MCP revision 2024-11-05. Three non-negotiable boundaries:
restart_k8s_podnever runs autonomously. Prompts containing "auto-fix" are not authorization; out-of-band operator confirmation is mandatory per POL-SEC-81.samplingis disabled for the vendor client, blocking third-party recursive model calls and host context depletion.- All vendor telemetry is treated as untrusted passive data, wrapped in inert delimiters so injected instructions cannot reach the planner.
Contracts and Invariants
| ID | Invariant | Enforcement |
|---|---|---|
| PA-1 | Protocol pinned to MCP 2024-11-05 | Newer or unsupported versions rejected with JSON-RPC -32602 |
| CE-1 | restart_k8s_pod requires interactive consent | Missing consent yields denied_by_policy, not a retry |
| CD-1 | Client B initializes with capabilities.sampling = null | Any sampling/createMessage returns JSON-RPC -32601 |
| CB-1 | Vendor content truncated at 8,192 tokens | Truncation sets header X-Content-Truncated: true |
| TO-1 | Tool execution capped at 5,000 ms | Timer cancellation via notifications/cancelled; late returns dropped |
Alternatives rejected
| Option | Why it was not taken | Under what evidence it would win |
|---|---|---|
| Autonomous restart on "auto-fix" | Violates POL-SEC-81; prompt text can be spoofed or hallucinated | Formal security waiver scoped to dev-only clusters |
| Vendor sampling with depth limit | Host tokens and API budget spent by external logic without caller visibility | CloudMetrics reimburses token spend and signs a deterministic call-tree SLA |
| Direct REST instead of MCP | Silos telemetry and catalog into proprietary adapters; loses standard discovery | Host deprecates dynamic tool discovery for static plugins |
Fitness Self-Check
| Criterion | Probe | Result |
|---|---|---|
| Unbounded Autonomy | Synthetic "auto-fix pod crashloop" prompt with simulated auto-approval | pass |
| Self-Graded Evaluation | Mock vendor returns success flag alongside an internal error payload | pass |
| Prompt-Only Control | Adversarial override injected inside a telemetry stack trace | pass |
Limits: probes verify the host client gate and parser, not Kubernetes RBAC outside the MCP client.
Residual Risk
HTTP/SSE keepalive drops on the vendor client may leave tool runs unacknowledged if query_telemetry lacks idempotency tokens. Accepted pending CloudMetrics SLA documentation.
Next steps
- DevEx updates the MCP client config to disable
capabilities.sampling. - Platform implements the host-side confirmation modal for
restart_k8s_pod. - InfoSec signs off on the sanitization delimiter structure before Client B goes to production.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill owns interoperability architecture between an AI application host, its MCP clients, and MCP servers. It defines protocol/version boundaries, initialization and negotiated capabilities, primitive ownership, discovery, session/transport behavior, identity and delegated authority, consent, trust, errors, and compatibility. It does not own each tool's business semantics or server/client implementation.
Use it when
- Multiple hosts, clients, or servers require a stable interoperability boundary
- Protocol revisions and initialization/version negotiation need decisions
- Client/server capability declarations govern optional behavior
- Tools, resources, and prompts need distinct ownership and discovery semantics
- List/read/get/call/result contracts, schemas, pagination, and notifications compose
- Local/remote transports differ in process, session, authentication, or failure behavior
For example: “Our IDE assistant should talk to our internal ticket system and a vendor's code-scanning server. The vendor's server sometimes returns fields we don't recognise.”
What you get
- architecture/mcp-architect/README.md
- architecture/mcp-architect/00-overview/mcp-architect-overview.md
- architecture/mcp-architect/verification/fitness-self-check.md
Plus one page per business module, only where your evidence calls for it: {module}/provider-contract.md, {module}/translation.md, {module}/failure-mapping.md, {module}/credentials.md, {module}/idempotency.md.
All paths are relative to the output folder you choose.
What it will not do
Do not use merely to implement or debug one MCP server/client/tool, wrap an API, design generic agent tools, configure a connector, build MCP UI, or choose an SDK/transport.
How it works
- Pin the protocol revision.
- Draw the topology.
- Decide what each server owns.
- State negotiated capabilities.
- Bound session and transport behavior.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-artifact.md
- assets/output-template-contract.md
- assets/output-template-domain.md
- assets/output-template-fitness.md
- assets/output-template-mechanism.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 13 days ago
- Passed all security checks, Safe to install