What is MCP Skills?

MCP Skills (Skills over MCP) is the official `io.modelcontextprotocol/skills` Extension for discovering Agent Skill metadata and retrieving verified `SKILL.md` instructions and supporting files through MCP Resources.

Quick Facts

Full NameSkills over Model Context Protocol
Created2026 as an official MCP Extension
SpecificationOfficial Specification

How It Works

Format, transport, and runtime

Agent Skills defines the directory and SKILL.md format, including frontmatter and optional scripts, references, and assets. MCP Skills defines how a Server advertises and transports those files. The Host or Agent Runtime decides whether a Skill is relevant, whether its instructions enter model context, and whether any referenced script or Tool may execute. Reading a Resource is neither Skill activation nor permission to act.

Capability and protocol methods

A Server supporting MCP Skills declares both Core resources and the io.modelcontextprotocol/skills Extension in server/discover. It implements skills/list for paginated discovery and skills/get for direct lookup or refresh. Skill content and supporting files are read with resources/read. Optional resources/directory/read is available only when the Extension advertises directoryRead: true; Clients must not infer support.

Identity and progressive loading

Skill identity is the pair of originating Server identity and Skill URI; names are searchable labels and are not globally unique. A Host can load a known URI without listing it, while a Server may return partial or empty listings. Clients should keep metadata light, fetch SKILL.md only after selection and approval, and read supporting files on demand. They must not prefetch all files during connection, listing, or approval.

Manifest integrity and caching

A stable Skill entry lists every file with URI, raw byte size, and SHA-256 digest. While the Skill remains active, the Host restricts reads to the retained manifest, verifies each file, and compares parsed SKILL.md frontmatter field by field. Persisted approval binds the complete URI-and-digest set; any added, removed, or changed file revokes it. Digests prove consistency with the Server's manifest, not that the content is trustworthy.

Trust and execution controls

Treat instructions, scripts, references, metadata, and nested Skill links as untrusted supply-chain input. Prevent same-name replacement, preserve origin through caches and restarts, isolate cached files from local Skill discovery, and require fresh approval before activating a nested Skill. Tool allowlists in frontmatter are hints, not Host authorization. Script execution, filesystem access, network egress, credentials, and every consequential Tool call need separate runtime policy.

Key Characteristics

  • Official optional Extension: identified by `io.modelcontextprotocol/skills` and paired with Core Resources
  • Separated layers: Agent Skills defines packages, MCP transports files, and the Host controls execution
  • Direct and listed discovery: `skills/get` works independently of partial `skills/list` results
  • Progressive disclosure: metadata, instructions, and supporting files load only as needed
  • Manifest verification: stable entries bind every URI to a SHA-256 digest and raw byte size
  • Origin-bound trust: Server identity plus Skill URI, approval, cache isolation, and runtime policy prevent silent substitution

Common Use Cases

  1. Distributing a shared code-review procedure and its checklist from the Server that owns the workflow
  2. Loading domain instructions only when an Agent selects the corresponding Skill
  3. Keeping remote policy templates versioned and verifiable across several Hosts
  4. Providing Skill references and assets without preloading the full package into model context
  5. Migrating a specialist Agent into shared instructions plus separately authorized MCP Tools

Example

loading...
Loading code...

Frequently Asked Questions

How is MCP Skills different from the Agent Skills specification?

Agent Skills defines the package format: a directory, `SKILL.md`, frontmatter, and optional supporting files. MCP Skills defines discovery and retrieval of those packages through MCP. A package can exist without MCP, and transporting it through MCP does not define how a particular Agent Runtime activates or executes it.

How is an MCP Skill different from an MCP Tool?

A Skill contains instructions and supporting resources that guide a workflow. A Tool is an executable operation with an input contract. Skills can describe when and how to use Tools, but loading instructions does not authorize a Tool call. Hosts and Servers still apply identity, object, argument, and side-effect policy.

Does verifying a Skill manifest prove the Skill is safe?

No. Size and SHA-256 checks prove that bytes match the retained Server manifest. They do not establish publisher trust, instruction quality, license, absence of Prompt Injection, or script safety. Provenance review, user approval, sandboxing, Tool policy, and behavior evaluation remain necessary.

Should a Host download every Skill file during discovery?

No. The Extension requires progressive retrieval. `skills/list` already carries metadata and a manifest; the Host reads `SKILL.md` after selection and supporting files only when required. Approval can bind the manifest without fetching the contents, reducing context, bandwidth, and exposure.

What happens when an MCP Skill changes after approval?

A changed, added, or removed file changes the retained manifest and revokes persisted approval. The Host refreshes the entry with `skills/get`, verifies the new manifest and files, shows the relevant change to the user or policy engine, and obtains fresh approval before loading or executing the new content.

Related Terms

Related Articles