Official agent skill

Cao MCP Apps

by awslabs in awslabs/cli-agent-orchestrator

Enable, operate, and extend CAO's MCP Apps surface — the host-rendered fleet dashboard visible inside MCP App hosts (Claude Desktop, ChatGPT, VS Code Copilot, Goose, Postman).

OfficialApache-2.0Auto-check passedAgent Workflows

Install Cao MCP Apps

skills CLI
$ npx skills add awslabs/cli-agent-orchestrator --skill cao-mcp-apps -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install awslabs/cli-agent-orchestrator cao-mcp-apps --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/awslabs/cli-agent-orchestrator.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cao-mcp-apps .claude/skills/cao-mcp-apps && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cao-mcp-apps
GitHub stars
1.4k
Token cost
~1.9k tokens
SKILL.md length
658 words
Files
6 (incl. scripts, references, assets)
Skills in repo
14
Repo updated
First seen
Licence
Apache-2.0

At a glance

Enable, operate, and extend CAO's MCP Apps surface — the host-rendered fleet dashboard visible inside MCP App hosts (Claude Desktop, ChatGPT, VS Code Copilot, Goose, Postman).

  • Works in 5 steps: Boots the E2E harness server (serves… → Drives Chromium through: dashboard →… → Records video… → …
  • The user says enable MCP Apps in CAO
  • SKILL.md covers Turn it on, What the operator gets, Full capability scope (what… and Gotchas, plus 2 more sections
  • Runs Shell scripts from its folder; calls npm, uv and curl

What it does

Cao MCP Apps is an agent skill from awslabs/cli-agent-orchestrator, published by the product's own GitHub organization. Enable, operate, and extend CAO's MCP Apps surface — the host-rendered fleet dashboard visible inside MCP App hosts (Claude Desktop, ChatGPT, VS Code Copilot, Goose, Postman). Use when the user says "enable MCP Apps in CAO", "the ui://cao views aren't rendering", "rebuild MCP Apps bundles", "add a new ui://cao/ view", or "configure the MCP Apps OAuth scope layer". Operates on the CAOMCPAPPSENABLED surface and caomcpapps/ build system. Not for the localhost:9889 browser dashboard, not for plugins, providers, or…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts, reference files and assets (for example `assets/mcp-apps-example.md`, `evals/evals.json` and `references/extending-views.md`). Compatibility notes: Requires CAOMCPAPPSENABLED=true, cao-server running, and an MCP App-capable host (SEP-1865).

It sits in Agent Workflows, covering MCP servers, Authentication and API testing. It works with Model Context Protocol, OpenAI, Postman and Visual Studio Code. The repository describes itself as: Multi-agent orchestration for AI coding CLIs — Claude Code, Kiro, Codex, and more, coordinated in isolated tmux sessions. The licence is Apache-2.0.

When your agent uses it

  • The user says enable MCP Apps in CAO
  • The ui://cao views arent rendering
  • Rebuild MCP Apps bundles
  • Add a new ui://cao/ view

Example prompts

  • “enable MCP Apps in CAO”
  • “the ui://cao views aren”
  • “rebuild MCP Apps bundles”
  • “/cao-mcp-apps”

Requirements

  • A Bash shell
  • Compatibility (from SKILL.md): Requires CAO_MCP_APPS_ENABLED=true, cao-server running, and an MCP App-capable host (SEP-1865).

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Boots the E2E harness server (serves built bundles in a real MCP-host iframe)
  2. Drives Chromium through: dashboard → agent detail → unified → event-stream
  3. Records video (docs/media/mcp-apps-demo.webm)
  4. Captures screenshots (docs/media/mcp-apps-{dashboard,agent,unified,event-stream}.png)
  5. Generates an optimized GIF (docs/media/mcp-apps-demo.gif) when ffmpeg is available

What it can do on your machine

Read from SKILL.md and the folder at commit 01c179a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • npm
    • uv
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • modelcontextprotocol.io
    • github.com
    • npmjs.com
    • apps.extensions.modelcontextprotocol.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires CAO_MCP_APPS_ENABLED=true, cao-server running, and an MCP App-capable host (SEP-1865).

    From compatibility in the SKILL.md frontmatter.

Context cost

Cao MCP Apps loads about 1.9k tokens when it runs, and up to ~4.1k if it reads all its reference files. Until then it costs about 139 tokens; SKILL.md has 658 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~139
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from awslabs/cli-agent-orchestrator at commit 01c179a, republished under its Apache-2.0 licence (© awslabs). 658 words, ~1,876 tokens.

Download SKILL.mdSave it as .claude/skills/cao-mcp-apps/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
cao-mcp-apps
description
Enable, operate, and extend CAO's MCP Apps surface — the host-rendered fleet dashboard visible inside MCP App hosts (Claude Desktop, ChatGPT, VS Code Copilot, Goose, Postman). Use when the user says "enable MCP Apps in CAO", "the ui://cao views aren't rendering", "rebuild MCP Apps bundles", "add a new ui://cao/* view", or "configure the MCP Apps OAuth scope layer". Operates on the CAO_MCP_APPS_ENABLED surface and cao_mcp_apps/ build system. Not for the localhost:9889 browser dashboard, not for plugins, providers, or session management.
compatibility
Requires CAO_MCP_APPS_ENABLED=true, cao-server running, and an MCP App-capable host (SEP-1865).

CAO MCP Apps

Operator + developer playbook for CAO's host-rendered fleet UI. Reference docs: docs/mcp-apps.md; example: examples/mcp-apps/.

Authoritative spec & sources of truth: MCP Apps Overview · Build an MCP App · capability negotiation · client matrix · stable spec 2026-01-26/apps.mdx (SEP-1865, Status: Stable) · SDK @modelcontextprotocol/ext-apps v1.7.4 (API ref · repo) · provenance PR #1865.

Turn it on

The surface is default-off. Enable and run:

bash
export CAO_MCP_APPS_ENABLED=true
uv run cao-server        # :9889 (REST + SSE /events)
uv run cao-mcp-server    # registers tools/resources via the mcp_apps plugin

It is packaged as the built-in mcp_apps plugin (cao.plugins entry-point). The plugin's on_mcp_server hook registers the ui://cao/* resources, the five app tools, the topology widget, and advertises the io.modelcontextprotocol/ui capability — best-effort and default-off, so nothing changes when the flag is unset.

What the operator gets

  • ui://cao/dashboard — fleet overview + the mutation entry point.
  • ui://cao/agent — one terminal's status, output tail, inbox, sub-agents.
  • ui://cao/event-stream — live governance ticker (app-only).
  • cao://widget/topology + /widgets/topology/ — build-free live event view.

All mutations flow through submit_command(kind, payload) — kinds: send_message, assign, create_session (standard); interrupt, pause, resume (lifecycle); shutdown_session (destructive). For full payload schemas and scope requirements per kind, see references/submit-command-kinds.md.

Full capability scope (what the views use)

Beyond tools/call, the views exercise the spec's bidirectional channel:

  • Host-delegated open-link (ui/open-link) — the dashboard shows "Open full Web UI ↗" → http://127.0.0.1:9889 only when the host advertises hostCapabilities.openLinks (gate on app.canOpenLinks(); the sandbox forbids window.open).
  • Display modes (ui/request-display-mode) — views declare availableDisplayModes: ["inline","fullscreen"] at ui/initialize.
  • Streamed tool input (ui/notifications/tool-input / -partial) — render before the result lands.
  • Model-context notes (ui/update-model-context) — body-free gesture summaries keep the agent aware without leaking message contents.

preferredFrameSize and requiredScopes are CAO additions, not spec _meta.ui fields (the spec sizes via containerDimensions + ui/notifications/size-changed); CAO requests no elevated permissions.

See assets/mcp-apps-example.md for a worked MCP Apps integration example.

Gotchas

  • Host doesn't offer the views → confirm CAO_MCP_APPS_ENABLED=true and that initialize advertises io.modelcontextprotocol/ui (the host must speak SEP-1865). Non-SEP-1865 hosts still get text-only tool results.
  • Views are blank / fail to load → the React bundles aren't built. Run cd cao_mcp_apps && npm ci && npm run build:all. The topology widget needs no build and is the quickest smoke test (curl /widgets/topology/topology.html).
  • Mutations rejected with 403 → the auth layer is enabled and the token lacks cao:write/cao:admin (cao:admin for delete_session). Unset AUTH0_DOMAIN/CAO_AUTH_JWKS_URI to disable enforcement.
  • Events don't stream → check GET /events (SSE) directly; the bus is drop-on-slow, so a stalled consumer silently loses events — re-hydrate via cao_fetch_history.
Show full SKILL.md (297 more words)Show less

Extending the surface

  • Agents emitting UI intents into this surface? Load the agui-author skill — it teaches how to call emit_ui with the six allow-listed components. Your emit_ui intents feed the L2 constructs that these views render.
  • Building or migrating an MCP App? Load the mcp-apps-builder skill first. It equips the official ext-apps Agent Skills (create-mcp-app, add-app-to-server, migrate-oai-app, convert-web-app) and the build guide. Use add-app-to-server when adding a new ui://cao/<name> view.
  • New command kind → add it to submit_command's classifier + router in mcp_server/app_tools.py (map to a real Backplane HTTP endpoint; never bypass the HTTP-only boundary) and to the scope pre-check.
  • New view → add a ui://cao/<name> resource in ext_apps/apps.py + an entry point under cao_mcp_apps/, build it, and tag the rendering tool with ui_meta(...). For the full step-by-step view creation procedure, see references/extending-views.md.
  • New host-delegated action → add a thin method on the McpApp bridge (cao_mcp_apps/src/shared/mcpApp.ts) that issues the spec ui/* request (e.g. openLink → ui/open-link, requestDisplayMode → ui/request-display-mode); gate UI on the matching hostCapabilities flag and cover it with a mockHost test.
  • Keep the boundary → mcp_server/* must reach state only over HTTP; the AST guard test (test/test_http_only_boundary.py) enforces it.
  • Keep bundles JIT-free → no eval/new Function (host CSP forbids it); the CI scan fails the build otherwise.

Recording & Verification

After building or modifying views, regenerate the demo media:

bash
cd cao_mcp_apps && npm run build:all && npm run demo

This runs scripts/record-demo.mjs which:

  1. Boots the E2E harness server (serves built bundles in a real MCP-host iframe)
  2. Drives Chromium through: dashboard → agent detail → unified → event-stream
  3. Records video (docs/media/mcp-apps-demo.webm)
  4. Captures screenshots (docs/media/mcp-apps-{dashboard,agent,unified,event-stream}.png)
  5. Generates an optimized GIF (docs/media/mcp-apps-demo.gif) when ffmpeg is available

The GIF is referenced in README.md and docs/mcp-apps.md — always regenerate after view changes so docs stay current.

Env overrides: CHROMIUM_BIN (path to Chrome), FFMPEG_BIN (for GIF), DEMO_PORT.

For a worked example of the full MCP Apps surface in action, see assets/mcp-apps-example.md.

© awslabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references, assets) in skills/cao-mcp-apps of awslabs/cli-agent-orchestrator.

  • SKILL.md
  • assets/mcp-apps-example.md
  • evals/evals.json
  • references/extending-views.md
  • references/submit-command-kinds.md
  • scripts/validate.sh

Open the folder on GitHubat commit 01c179a

Compare with similar skills

Cao MCP Apps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cao MCP Apps compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cao MCP Apps this skillawslabs/cli-agent-orchestrator1.4k—~1.9kAutomated safety check: PassApache-2.0
External AgentsBuilderIO/agent-native7.1k—~7.2kAutomated safety check: NotesNone
Xquik MCPXquik-dev/x-twitter-scraper2111 repos~997Automated safety check: PassMIT
Setup MCP Servernesquikm/mcp-rubber-duck178—~1.3kAutomated safety check: NotesMIT
UI Widget Developermicrosoft/work-iq1k—~6.1kAutomated safety check: NotesCustom licence
MCP Server Builder with mcp-usemcp-use/mcp-use11k—~923Automated safety check: PassApache-2.0

Similar skills

  • External Agents

    BuilderIO/agent-native

    Connect external agents and MCP hosts (Claude, Claude Desktop, Claude Code, ChatGPT custom MCP apps, Codex, Cursor, Claude Cowork, VS Code GitHub Copilot, Goose, Postman, MCPJam) to an agent-native…

    7.1k GitHub stars~7.2k tokensUpdated yesterday
    MobileAuto-check: notes
  • Xquik MCP

    Xquik-dev/x-twitter-scraper

    Connect, verify, and troubleshoot Xquik's remote MCP server.

    211 GitHub starsUsed in 1 repo~997 tokens
    Backend & APIsAuto-check passed
  • Setup MCP Server

    nesquikm/mcp-rubber-duck

    Add mcp-rubber-duck MCP server to an AI coding tool (Claude Desktop, Cursor, VS Code, Windsurf, etc.)

    178 GitHub stars~1.3k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check: notes
  • UI Widget Developer

    microsoft/work-iq

    Official

    Build MCP servers for Copilot Chat using the OpenAI Apps SDK or MCP Apps SDK widget rendering support (any language).

    1k GitHub stars~6.1k tokensUpdated yesterday
    Agent WorkflowsAuto-check: notes
  • Builds, modifies, debugs, migrates and verifies TypeScript MCP servers and MCP Apps with the mcp-use framework, treating the installed package's types as the source of truth.

    11k GitHub stars~923 tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Cross Origin Iframe Probe

    jumodada/Drissionpage-MCP-Server

    A skill your agent uses when a drissionpage-mcp task targets an iframe such as a payment widget, challenge, SSO flow, or embedded checkout.

    487 GitHub stars~1.2k tokensUpdated 27 days ago
    Agent WorkflowsAuto-check passed

More from awslabs/cli-agent-orchestrator

All 14 skills in this repo
  • Agui Author

    awslabs/cli-agent-orchestrator

    Official

    Author live dashboard UI from an agent via the emitui MCP tool.

    1.4k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • MCP Apps Builder

    awslabs/cli-agent-orchestrator

    Official

    Load the official MCP Apps builder skills (create-mcp-app, migrate-oai-app, add-app-to-server, convert-web-app) from github.com/modelcontextprotocol/ext-apps.

    1.4k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Cao Plugin

    awslabs/cli-agent-orchestrator

    Official

    Create a new CAO (CLI Agent Orchestrator) plugin. An agent skill from awslabs/cli-agent-orchestrator.

    1.4k GitHub stars~3.1k tokensUpdated today
    Auto-check: notes
  • Cao Provider

    awslabs/cli-agent-orchestrator

    Official

    Create a new CLI agent provider for CAO (CLI Agent Orchestrator).

    1.4k GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Cao Agent Routing

    awslabs/cli-agent-orchestrator

    Official

    Find and select the best installed CAO agent profile for a task before delegating with assign or handoff.

    1.4k GitHub stars~552 tokensUpdated today
    Auto-check passed
  • Cao Contributing

    awslabs/cli-agent-orchestrator

    Official

    Contribute changes to the CAO (CLI Agent Orchestrator) codebase — the local dev loop, the CI gate map, and the pre-PR checklist.

    1.4k GitHub stars~4.1k tokensUpdated today
    Auto-check passed

Questions about Cao MCP Apps

What does Cao MCP Apps do?

Enable, operate, and extend CAO's MCP Apps surface — the host-rendered fleet dashboard visible inside MCP App hosts (Claude Desktop, ChatGPT, VS Code Copilot, Goose, Postman). Cao MCP Apps is an agent skill from awslabs/cli-agent-orchestrator, published by the product's own GitHub organization. Enable, operate, and extend CAO's MCP Apps surface — the host-rendered fleet dashboard visible inside MCP App hosts (Claude Desktop, ChatGPT, VS Code Copilot, Goose, Postman).

When should I use Cao MCP Apps?

Cao MCP Apps fits situations like: the user says enable MCP Apps in CAO; the ui://cao views arent rendering; rebuild MCP Apps bundles; add a new ui://cao/ view.

How do I install Cao MCP Apps in Claude Code?

Run `npx skills add awslabs/cli-agent-orchestrator --skill cao-mcp-apps -a claude-code`. Or copy the skill folder (skills/cao-mcp-apps in awslabs/cli-agent-orchestrator) into .claude/skills/cao-mcp-apps in your project. Claude Code loads it when a task matches its description.

How do I install Cao MCP Apps in Codex?

Run `npx skills add awslabs/cli-agent-orchestrator --skill cao-mcp-apps -a codex`. Or copy the skill folder (skills/cao-mcp-apps in awslabs/cli-agent-orchestrator) into .agents/skills/cao-mcp-apps in your project. Codex loads it when a task matches its description.

Can I use Cao MCP Apps in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add awslabs/cli-agent-orchestrator --skill cao-mcp-apps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cao-mcp-apps, .gemini/skills/cao-mcp-apps, .github/skills/cao-mcp-apps and .opencode/skills/cao-mcp-apps in your project.

What does Cao MCP Apps need to run?

Going by SKILL.md and its folder, Cao MCP Apps needs a shell for the scripts in its folder and the command-line tools its instructions call (npm, uv and curl). Our summary lists: A Bash shell. Compatibility (from SKILL.md): Requires CAO_MCP_APPS_ENABLED=true, cao-server running, and an MCP App-capable host (SEP-1865)..

Does Cao MCP Apps access the network?

SKILL.md names 4 domains. As links in the text: modelcontextprotocol.io, github.com, npmjs.com and apps.extensions.modelcontextprotocol.io. This is read from the text; nothing was executed.

Is Cao MCP Apps safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Cao MCP Apps use?

Cao MCP Apps is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cao MCP Apps use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.

What are the alternatives to Cao MCP Apps?

Skills that share tags, products or a category with Cao MCP Apps: External Agents (BuilderIO/agent-native, 7.1k stars), Xquik MCP (Xquik-dev/x-twitter-scraper, 211 stars), Setup MCP Server (nesquikm/mcp-rubber-duck, 178 stars) and UI Widget Developer (microsoft/work-iq, 1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cao MCP Apps?

awslabs (a GitHub organization, an official publisher) maintains it in awslabs/cli-agent-orchestrator, which has 1,406 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 11, 2026.

Source: awslabs/cli-agent-orchestrator on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.