Quarkus Security
affaan-m/ECC
Quarkus security implementation patterns: JWT and OIDC authentication, @RolesAllowed RBAC and SecurityIdentity checks, Bean Validation and custom validators, parameterized Panache queries, BCrypt…
A skill your agent uses when configuring a FrontMCP server through frontmcp.config or the @FrontMcp options.
$ npx skills add agentfront/frontmcp --skill frontmcp-config -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install agentfront/frontmcp frontmcp-config --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/agentfront/frontmcp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/libs/skills/catalog/frontmcp-config .claude/skills/frontmcp-config && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "frontmcp-config" agent skill from https://github.com/agentfront/frontmcp/tree/main/libs/skills/catalog/frontmcp-config into .claude/skills/frontmcp-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frontmcp-config", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/agentfront/frontmcp/tree/main/libs/skills/catalog/frontmcp-configType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add agentfront/frontmcp --skill frontmcp-config -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install agentfront/frontmcp frontmcp-config --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/agentfront/frontmcp.git skills-src && mkdir -p .agents/skills && cp -r skills-src/libs/skills/catalog/frontmcp-config .agents/skills/frontmcp-config && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "frontmcp-config" agent skill from https://github.com/agentfront/frontmcp/tree/main/libs/skills/catalog/frontmcp-config into .agents/skills/frontmcp-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frontmcp-config", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add agentfront/frontmcp --skill frontmcp-config -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install agentfront/frontmcp frontmcp-config --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/agentfront/frontmcp.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/libs/skills/catalog/frontmcp-config .cursor/skills/frontmcp-config && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "frontmcp-config" agent skill from https://github.com/agentfront/frontmcp/tree/main/libs/skills/catalog/frontmcp-config into .cursor/skills/frontmcp-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frontmcp-config", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/agentfront/frontmcp.git --path libs/skills/catalog/frontmcp-config--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add agentfront/frontmcp --skill frontmcp-config -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install agentfront/frontmcp frontmcp-config --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/agentfront/frontmcp.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/libs/skills/catalog/frontmcp-config .gemini/skills/frontmcp-config && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "frontmcp-config" agent skill from https://github.com/agentfront/frontmcp/tree/main/libs/skills/catalog/frontmcp-config into .gemini/skills/frontmcp-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frontmcp-config", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install agentfront/frontmcp frontmcp-configInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add agentfront/frontmcp --skill frontmcp-config -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/agentfront/frontmcp.git skills-src && mkdir -p .github/skills && cp -r skills-src/libs/skills/catalog/frontmcp-config .github/skills/frontmcp-config && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "frontmcp-config" agent skill from https://github.com/agentfront/frontmcp/tree/main/libs/skills/catalog/frontmcp-config into .github/skills/frontmcp-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frontmcp-config", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add agentfront/frontmcp --skill frontmcp-config -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install agentfront/frontmcp frontmcp-config --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/agentfront/frontmcp.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/libs/skills/catalog/frontmcp-config .opencode/skills/frontmcp-config && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "frontmcp-config" agent skill from https://github.com/agentfront/frontmcp/tree/main/libs/skills/catalog/frontmcp-config into .opencode/skills/frontmcp-config/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frontmcp-config", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
frontmcp-configA skill your agent uses when configuring a FrontMCP server through frontmcp.config or the @FrontMcp options.
Frontmcp Config is an agent skill from agentfront/frontmcp. Use when configuring a FrontMCP server through frontmcp.config or the @FrontMcp options. Covers auth modes (public, transparent, local, remote), OAuth plus credential vault and secureStore, CORS, HTTP port / entry-path prefix / unix socket, security headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options), rate limiting / throttling / concurrency / timeout / IP filtering (GuardConfig), session storage (Redis, Vercel KV), client transport protocols (SSE, Streamable HTTP, stateless, protocol presets)…
Its SKILL.md is about 7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 69 other files, including reference files (for example `examples/configure-auth-modes/local-behind-tunnel.md`, `examples/configure-auth-modes/local-consent-enforcement.md` and `examples/configure-auth-modes/local-dcr-control.md`).
It sits in Backend & APIs, covering Rate limiting, Authentication and Secure coding. It works with Vercel, Redis and Model Context Protocol. The repository describes itself as: TypeScript-first framework for the Model Context Protocol (MCP). You write clean, typed code; FrontMCP handles the protocol, transport, DI, session/auth, and execution flow. The licence is Apache-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 8f59ba8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.agentfront.devFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Frontmcp Config loads about 7k tokens when it runs, and up to ~55k if it reads all its reference files. Until then it costs about 208 tokens; SKILL.md has 1,603 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from agentfront/frontmcp at commit 8f59ba8, republished under its Apache-2.0 licence (© agentfront). 1,603 words, ~6,998 tokens.
.claude/skills/frontmcp-config/SKILL.md (or your agent's skills folder). This skill also uses 65 other files; get the full folder from GitHub.Entry point for configuring FrontMCP servers. This skill helps you find the right configuration reference (under references/) based on what aspect of your server you need to set up.
configure-transport, configure-auth, etc.)frontmcp-development)frontmcp-deployment)Decision: Use this skill when you need to figure out WHAT to configure. Open the matching reference under
references/directly when you already know.
frontmcp create (see frontmcp-setup)references/configure-transport.md, references/configure-auth.md) for detailed instructions@FrontMcp or @App decorator| Scenario | Reference | Description |
|---|---|---|
| Choose between SSE, Streamable HTTP, or stdio | configure-transport | Transport protocol selection with distributed session options |
| Set up CORS, port, base path, or request limits | configure-http | HTTP server options for Streamable HTTP and SSE transports |
| Add rate limiting, concurrency, or IP filtering | configure-throttle | Server-level and per-tool throttle configuration |
| Enable tools to ask users for input | configure-elicitation | Elicitation schemas, stores, and multi-step flows |
| Set up authentication (public, transparent, local, remote) | configure-auth | OAuth flows, credential vault, multi-app auth |
| Configure session storage backends | configure-session | Memory, Redis, Vercel KV, and custom session stores |
| Add Redis for production storage | setup-redis | Docker Redis, Vercel KV, pub/sub for distributed subscriptions |
| Add SQLite for local development | setup-sqlite | SQLite with WAL mode, migration helpers |
| Understand auth mode details (public/transparent/local/remote) | configure-auth-modes | Authentication mode details (public, transparent, local, remote) |
| Fine-tune guard configuration for throttling | configure-throttle-guard-config | Advanced guard configuration for throttling |
| Use transport protocol presets | configure-transport-protocol-presets | Transport protocol preset configurations |
| Configure multi-target deployments and frontmcp.config.ts | configure-deployment-targets | Typed config with defineConfig(), 9 deployment targets, JSON schema |
| Add CSP, HSTS, X-Frame-Options, and other security headers | configure-security-headers | CSP directives, report-only mode, HSTS preload, custom headers |
| Configure skills HTTP, instructions injection, or audit log | configure-skills-http | Full skillsConfig reference: auth, cache, instructions, audit log |
Split apps into separate scopes (splitByApp) | decorators-guide | Per-app scope and basePath isolation on @FrontMcp |
| Enable widget-to-host communication (ext-apps) | decorators-guide | extApps host capabilities, session validation, widget comms |
| Enable background jobs and workflows | decorators-guide | jobs: { enabled: true, store? } on @FrontMcp |
| Configure pagination for list operations | decorators-guide | pagination defaults for tools/list endpoint |
| Configure npm/ESM package loader for remote apps | decorators-guide | loader config for App.esm() / App.remote() resolution |
FrontMCP configuration cascades through three layers:
Server (@FrontMcp) ← Global defaults
└── App (@App) ← App-level overrides
└── Tool (@Tool) ← Per-tool overrides| Setting | Server (@FrontMcp) | App (@App) | Tool (@Tool) |
|---|---|---|---|
| Transport | Yes | No | No |
| HTTP (CORS, port) | Yes | No | No |
| Throttle (rate limit) | Yes (throttle global defaults) | No | Yes (rateLimit, concurrency, timeout) |
| Auth mode | Yes | Yes (override) | No |
| Auth providers | No | Yes (authProviders) | Yes (authProviders) |
| Session store | Yes | No | No |
| Elicitation | Yes (enable: elicitation) | No | Yes (usage: this.elicit()) |
| ExtApps | Yes | No | No |
| Jobs / Workflows | Yes (jobs: { enabled }) | No | No |
| Pagination | Yes | No | No |
| SplitByApp | Yes | No | No |
| Pattern | Rule |
|---|---|
| Auth + session | Auth mode determines session requirements: remote needs Redis/KV; public can use memory |
| Transport + storage | Stateless transports (serverless) require distributed storage; stateful (Node) can use in-process |
| Throttle scope | Server-level throttle applies to all tools; per-tool throttle overrides for specific tools |
| Environment config | Use environment variables for all secrets (API keys, Redis URLs, OAuth credentials) |
| Config validation | FrontMCP validates config at startup; invalid config throws before the server starts |
| Pattern | Correct | Incorrect | Why |
|---|---|---|---|
| Auth mode for dev | auth: { mode: 'public' } or auth: { mode: 'transparent', provider: '...' } locally | auth: { mode: 'remote', ... } with real OAuth in dev | Remote auth requires a running OAuth provider; public/transparent are simpler for local dev |
| Session store | Redis for production, memory for development | Memory for production | Memory sessions are lost on restart and don't work across serverless invocations |
| Rate limit placement | Server-level for global limits, per-tool for expensive operations | Only server-level | Some tools are cheap (list) and some are expensive (generate); per-tool limits prevent abuse of expensive tools |
| CORS config | Explicit allowed origins in production | cors: { origin: '*' } in production | Wildcard CORS allows any origin to call your server |
| Config secrets | process.env.REDIS_URL via environment variable | Hardcoded redis://localhost:6379 in source | Hardcoded secrets leak to git and break in different environments |
| Problem | Cause | Solution |
|---|---|---|
| Server fails to start with config error | Invalid or missing required config field | Check the error message; FrontMCP validates config at startup and reports the specific invalid field |
| CORS blocked in browser | Missing or incorrect CORS origin config | Add the client's origin to http.cors.origin; see configure-http |
| Rate limit too aggressive | Global limit applied to all tools | Add per-tool overrides for cheap tools with higher limits; see configure-throttle |
| Sessions lost on serverless | Using memory session store on stateless platform | Switch to Redis or Vercel KV; see configure-session |
| Auth callback fails | OAuth redirect URI mismatch | Ensure the redirect URI registered with your OAuth provider matches the server's /oauth/callback endpoint; see configure-auth |
Each reference has matching examples under examples/<reference>/:
configure-auth-modes| Example | Level | Description |
|---|---|---|
local-self-signed-tokens | Intermediate | Configure a server that signs its own JWT tokens with consent and incremental auth enabled. |
remote-enterprise-oauth | Advanced | Proxy auth to one mandatory upstream IdP, mint a FrontMCP session, read the upstream token. |
transparent-jwt-validation | Basic | Validate externally-issued JWTs without managing token lifecycle on the server. |
configure-auth| Example | Level | Description |
|---|---|---|
multi-app-auth | Advanced | Configure a single FrontMCP server with multiple apps, each using a different auth mode -- public for open endpoints and remote for admin endpoints. |
public-mode-setup | Basic | Set up a FrontMCP server with public (unauthenticated) access and anonymous scopes. |
remote-oauth-with-vault | Intermediate | Configure a FrontMCP server with remote OAuth 2.1 authentication and use the credential vault to call downstream APIs on behalf of the authenticated user. |
configure-elicitation| Example | Level | Description |
|---|---|---|
basic-confirmation-gate | Basic | Request user confirmation before executing a destructive action. |
distributed-elicitation-redis | Intermediate | Configure elicitation with Redis storage for multi-instance production deployments. |
configure-http| Example | Level | Description |
|---|---|---|
cors-restricted-origins | Basic | Configure CORS to allow only specific frontend origins with credentials. |
entry-path-reverse-proxy | Intermediate | Mount the MCP server under a URL prefix for reverse proxy or multi-service setups. |
unix-socket-local | Intermediate | Bind the server to a unix socket instead of a TCP port for local-only communication. |
configure-session| Example | Level | Description |
|---|---|---|
multi-server-key-prefix | Intermediate | Use unique key prefixes when multiple FrontMCP servers share one Redis instance. |
redis-session-store | Basic | Configure Redis-backed session storage for production deployments. |
vercel-kv-session | Intermediate | Configure Vercel KV for session storage in serverless Vercel deployments. |
configure-throttle-guard-config| Example | Level | Description |
|---|---|---|
full-guard-config | Advanced | Complete GuardConfig using every available field for maximum protection. |
minimal-guard-config | Basic | Enable throttle with just a global rate limit and default timeout. |
configure-throttle| Example | Level | Description |
|---|---|---|
distributed-redis-throttle | Advanced | Configure Redis-backed rate limiting for multi-instance deployments behind a load balancer. |
per-tool-rate-limit | Intermediate | Override server defaults with per-tool rate limits and concurrency caps. |
server-level-rate-limit | Basic | Configure global rate limits and IP filtering at the server level. |
configure-transport-protocol-presets| Example | Level | Description |
|---|---|---|
legacy-preset-nodejs | Basic | Use the default legacy preset for maximum compatibility with all MCP clients. |
stateless-api-serverless | Intermediate | Use the stateless-api preset for Vercel, Lambda, or Cloudflare Workers. |
configure-transport| Example | Level | Description |
|---|---|---|
custom-protocol-flags | Advanced | Override individual protocol flags instead of using a preset for fine-grained control. |
distributed-sessions-redis | Intermediate | Configure transport with Redis persistence for multi-instance load-balanced deployments. |
stateless-serverless | Basic | Configure stateless transport for Vercel, Lambda, or Cloudflare deployments. |
configure-deployment-targets| Example | Level | Description |
|---|---|---|
multi-target-with-security | Intermediate | Configure a FrontMCP project with node + distributed targets, CSP headers, and HSTS |
distributed-ha-config | Advanced | Configure a distributed deployment target with HA settings for heartbeat, session takeover, and Redis-backed session persistence |
json-schema-ide-support | Basic | Use frontmcp.config.json with JSON Schema for VS Code and WebStorm autocomplete |
configure-security-headers| Example | Level | Description |
|---|---|---|
csp-report-only | Basic | Test CSP policies in report-only mode to identify violations before enforcement |
full-production-headers | Intermediate | Complete security headers configuration for production with CSP enforcement, HSTS preload, and clickjacking protection |
Skills are distributed as plain SKILL.md files plus a sibling references/
and examples/ tree, so consumers can pick whichever access mode fits:
| Mode | How it works |
|---|---|
| Filesystem | Read libs/skills/catalog/frontmcp-config/ directly from a clone of the catalog repo, or from a published @frontmcp/skills install. SKILL.md is the entry point. |
frontmcp CLI | frontmcp skills list, frontmcp skills read frontmcp-config, frontmcp skills read frontmcp-config:references/<file>.md, frontmcp skills install frontmcp-config — no server required. |
MCP skill:// | When a developer mounts this skill into their own FrontMCP server (@FrontMcp({ skills: [...] })), the SDK exposes it via SEP-2640 resources: skill://frontmcp-config/SKILL.md, skill://frontmcp-config/references/{file}.md, etc. The server’s skill://index.json returns the SEP-2640 discovery document for everything mounted on it. |
The catalog itself is not an MCP server. The skill:// URIs only resolve
when a server has been configured to host this skill.
configure-transport, configure-http, configure-throttle, configure-elicitation, configure-auth, configure-session, setup-redis, setup-sqlite© agentfront, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 65 other files (references) in libs/skills/catalog/frontmcp-config of agentfront/frontmcp.
Open the folder on GitHubat commit 8f59ba8
Frontmcp Config next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Frontmcp Config this skillagentfront/frontmcp | 146 | — | ~7k | Automated safety check: Pass | Apache-2.0 | |
| Quarkus Securityaffaan-m/ECC | 275k | 1 repos | ~3.1k | Automated safety check: Pass | MIT | |
| FoundatioFoundatioFx/Foundatio | 2.1k | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | |
| Frappe Core APIImpertio-Studio/Frappe_Claude_Skill_Package | 187 | 1 repos | ~3.2k | Automated safety check: Pass | MIT | |
| Frappe Errors APIImpertio-Studio/Frappe_Claude_Skill_Package | 187 | 1 repos | ~4k | Automated safety check: Pass | MIT | |
| Azure APIM Policy Authoringthomast1906/github-copilot-agent-skills | 202 | — | ~1.5k | Automated safety check: Pass | MIT |
affaan-m/ECC
Quarkus security implementation patterns: JWT and OIDC authentication, @RolesAllowed RBAC and SecurityIdentity checks, Bean Validation and custom validators, parameterized Panache queries, BCrypt…
FoundatioFx/Foundatio
A skill your agent uses when working with Foundatio infrastructure abstractions for .NET -- caching, queuing, messaging, file storage, distributed locking, or background jobs.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when building ERPNext/Frappe API integrations (v14/v15/v16) including REST API, RPC API, authentication, webhooks, and rate limiting.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when debugging or handling API errors in Frappe/ERPNext v14/v15/v16.
thomast1906/github-copilot-agent-skills
Generates Azure API Management policy XML for authentication, rate limiting, CORS, error handling and transformations, consulting Azure best-practice and documentation tools first.
rand/cc-polymath
Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.
agentfront/frontmcp
A skill your agent uses when customizing, branding, or replacing the built-in FrontMCP OAuth pages (the login, consent, federated-select, incremental-authorization, and error pages) with your own…
agentfront/frontmcp
A skill your agent uses when pushing real-time notifications or events into Claude Code (or another MCP client) sessions, or building two-way chat bridges.
agentfront/frontmcp
A skill your agent uses when extending FrontMCP beyond the core SDK by integrating external npm packages, libraries, or third-party services into providers and tools.
agentfront/frontmcp
A skill your agent uses when adding tracing, structured logging, metrics, or monitoring to a FrontMCP server.
agentfront/frontmcp
A skill your agent uses when implementing authorization and access control for FrontMCP tools, resources, prompts, or skills, deciding who may invoke what.
agentfront/frontmcp
A skill your agent uses when deploying, building for production, packaging, or shipping a FrontMCP server.
Works with
Categories
A skill your agent uses when configuring a FrontMCP server through frontmcp.config or the @FrontMcp options. Frontmcp Config is an agent skill from agentfront/frontmcp.config or the @FrontMcp options.
Frontmcp Config fits situations like: configuring a FrontMCP server through frontmcp.config; the @FrontMcp options.
Run `npx skills add agentfront/frontmcp --skill frontmcp-config -a claude-code`. Or copy the skill folder (libs/skills/catalog/frontmcp-config in agentfront/frontmcp) into .claude/skills/frontmcp-config in your project. Claude Code loads it when a task matches its description.
Run `npx skills add agentfront/frontmcp --skill frontmcp-config -a codex`. Or copy the skill folder (libs/skills/catalog/frontmcp-config in agentfront/frontmcp) into .agents/skills/frontmcp-config in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agentfront/frontmcp --skill frontmcp-config -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/frontmcp-config, .gemini/skills/frontmcp-config, .github/skills/frontmcp-config and .opencode/skills/frontmcp-config in your project.
SKILL.md names no scripts, command-line tools or credentials: Frontmcp Config is instructions for the agent only. Our summary lists: Node.js; Docker.
SKILL.md names 1 domain. As links in the text: docs.agentfront.dev. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Frontmcp Config is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 7k tokens (SKILL.md is roughly 28k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 48k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Frontmcp Config: Quarkus Security (affaan-m/ECC, 275k stars), Foundatio (FoundatioFx/Foundatio, 2.1k stars), Frappe Core API (Impertio-Studio/Frappe_Claude_Skill_Package, 187 stars) and Frappe Errors API (Impertio-Studio/Frappe_Claude_Skill_Package, 187 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
agentfront (a GitHub organization) maintains it in agentfront/frontmcp, which has 146 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 7, 2026.
Source: agentfront/frontmcp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.