MCP Server Builder
anthropics/skills
Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.
Write the brief for a single independent cold reviewer and grade what it returns, keeping it isolated from the panel that already graded the change.
$ npx skills add Cotal-AI/Cotal --skill cold-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Cotal-AI/Cotal cold-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Cotal-AI/Cotal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/cold-review .claude/skills/cold-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cold-review" agent skill from https://github.com/Cotal-AI/Cotal/tree/main/.claude/skills/cold-review into .claude/skills/cold-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cold-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Cotal-AI/Cotal/tree/main/.claude/skills/cold-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Cotal-AI/Cotal --skill cold-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Cotal-AI/Cotal cold-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Cotal-AI/Cotal.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/cold-review .agents/skills/cold-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cold-review" agent skill from https://github.com/Cotal-AI/Cotal/tree/main/.claude/skills/cold-review into .agents/skills/cold-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cold-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Cotal-AI/Cotal --skill cold-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Cotal-AI/Cotal cold-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Cotal-AI/Cotal.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/cold-review .cursor/skills/cold-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cold-review" agent skill from https://github.com/Cotal-AI/Cotal/tree/main/.claude/skills/cold-review into .cursor/skills/cold-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cold-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Cotal-AI/Cotal.git --path .claude/skills/cold-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Cotal-AI/Cotal --skill cold-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Cotal-AI/Cotal cold-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Cotal-AI/Cotal.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/cold-review .gemini/skills/cold-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cold-review" agent skill from https://github.com/Cotal-AI/Cotal/tree/main/.claude/skills/cold-review into .gemini/skills/cold-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cold-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Cotal-AI/Cotal cold-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Cotal-AI/Cotal --skill cold-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Cotal-AI/Cotal.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/cold-review .github/skills/cold-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cold-review" agent skill from https://github.com/Cotal-AI/Cotal/tree/main/.claude/skills/cold-review into .github/skills/cold-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cold-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Cotal-AI/Cotal --skill cold-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Cotal-AI/Cotal cold-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Cotal-AI/Cotal.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/cold-review .opencode/skills/cold-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cold-review" agent skill from https://github.com/Cotal-AI/Cotal/tree/main/.claude/skills/cold-review into .opencode/skills/cold-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cold-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cold-reviewWrite the brief for a single independent cold reviewer and grade what it returns, keeping it isolated from the panel that already graded the change.
Cold Review is an agent skill from Cotal-AI/Cotal. Write the brief for a single independent cold reviewer and grade what it returns, keeping it isolated from the panel that already graded the change. Read by whoever AUTHORS the brief; the graded seat never loads this file. Covers what the seat is given, what its verdict binds, who may override it, and how the rules degrade when the vendor set is short. Use when a panel has reached consensus and you want a second opinion consensus cannot anchor, when a change is security-sensitive or hard to reverse, or when you…
Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Agent Workflows. It works with Model Context Protocol. The repository describes itself as: The open standard for agent coordination. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit a64403e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cold Review loads about 4.2k tokens when it runs. Until then it costs about 151 tokens; SKILL.md has 2,698 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Cotal-AI/Cotal at commit a64403e, republished under its Apache-2.0 licence (© Cotal-AI). 2,698 words, ~4,234 tokens.
.claude/skills/cold-review/SKILL.md (or your agent's skills folder).A cold reviewer is not an extra panelist. It is a control on the panel.
A panel converges. Reviewers read each other, findings get confirmed by seats already looking in the same direction, and the group arrives somewhere with more confidence than any member earned alone. That convergence is usually right, which is why it is dangerous when it is wrong: a panel of three has approved a head carrying a defect all three missed, and what surfaced it was a differently framed read, not a fourth verifier.
This file is read by the person who WRITES the brief, not by the seat being briefed. The value is in the brief, not in the seat's context. A cold seat that never loaded a skill file, never joined the mesh and received nothing but a persona has produced three blockers that two fully-briefed lenses missed. So nothing here requires the graded seat to have access to this document, and no rule below may be written so that it does.
Why never join, stated correctly. Joining exposes the seat to the panel's live traffic for as
long as it is subscribed, and the panel is active during a cold read. Replay of history is a second
exposure path but not a guaranteed one: replay is channel.replay ?? defaults.replay ?? true, a
default-true policy with a per-channel override, so a replay=false channel would not replay. The
rule does not depend on that setting in either direction, and a brief that justifies it by replay
alone is resting on a config it cannot rely on.
Prefer the ACL to the request. subscribe: [] plus an allowSubscribe that excludes the panel
channel makes non-join a property of the seat rather than an instruction it must follow. Where a
fence exists, use the fence.
If you catch yourself wanting to tell it something so it does not waste effort, that is the anchor forming. Let it waste the effort; that is the price of the control, and it is cheap next to a laundered verdict.
It must be executable without a follow-up question, because a follow-up is the contact the isolation forbids. A brief that omits the operational half forces the seat to come back and ask.
The substance, and nothing beyond it:
The operations, all of which are required and none of which anchor:
What must never appear: the issue's own diagnosis, the author's rationale, "the tricky part is X", the panel's findings in any form, or a question phrased as confirmation. Ask "what does this change accept that it should not, and what does it reject that it should not" and let the seat derive the set. Never "do you agree that".
If the author believes something is weak, that belief goes to the panel, which benefits from it. The cold seat's job is to find what nobody framed.
A verdict that exists only in a manager's context is not a verdict. It must land somewhere that survives the seat and the manager, and the seat must put it there itself, because a relayed verdict cannot be distinguished from an invented one.
The broker-attested destination is a Cotal mesh post on one dedicated record channel that the cold
seat may publish only to and the panel cannot read. The cold persona keeps subscribe: [] and
allowSubscribe: [], and grants allowPublish only for that record channel. Publishing the verdict
does not require joining it.
A file at an absolute path written into the seat's persona remains an explicit fallback when the
record-channel route is unavailable. It is first-hand delivery only as a norm and cannot satisfy a
gate that requires broker-attested poster identity. A GitHub comment is not a substitute: it
identifies the workstation's GitHub account, not the Cotal seat, and a shared gh credential lets the
manager post the same comment.
Poster is a control only on the Cotal broker-attested destination. A mesh post carries the Cotal principal the broker records. A GitHub comment carries a GitHub account and does not bind that account to the Cotal seat. A file at an absolute path carries neither: any process that can write that path can produce the artifact, including the manager who later "confirms" it by re-reading it. First-hand file delivery is therefore a norm on the seat and the briefer, not a control a later stranger can verify. A gate that treats the file's existence as proof the seat posted has accepted a relay. When the brief must use a file, say so in the verdict record, and do not list poster or channel membership among the checkable controls for that delivery.
Verify at the destination, never at the source. Re-fetch the landed artifact and grep it for content you expect, with a positive control so an empty fetch cannot pass as a clean result. Writes that report success and do not land are common, including an edit that reports nothing and changes nothing or a file write that does not persist while the tree reports clean.
APPROVE, or named blockers. Never an open-ended re-read, never "looks fine so far", never a list of things it might check next.
It must separate what it EXERCISED from what it INSPECTED, and the split is defined by the OBJECT, not the verb: exercised means the reviewed artifact itself ran through a real entry point. Running a tool to read the artifact, testing against a mock, compiling, or a dry run are inspection. A verb list cannot settle those cases and two seats will classify them differently.
Where it could not exercise something, it names the gap and why. A named gap is a limit of the ENVIRONMENT, not a licence for a limit of EFFORT. "I graded this by reading because running it would take the fleet down" is a boundary on what is knowable; "I did not get to that part" is a boundary on what was attempted, and the two must never be written in the same words.
A blocking finding must enumerate the attacks that FAILED. Without the survey, one success reads as a lucky hit; with it, the finding is a surveyed surface with one hole, and the fixer learns which ground is already covered.
A cold verdict is not a veto. It is binding as a question that must be answered at the artifact, publicly.
This matters because isolation defends against panel anchoring and not against error anchoring. If the panel disproved claim C with evidence E, the cold seat may re-derive C and report it with fresh confidence, and every route back to it is forbidden: showing E is showing findings, saying "C is settled" is a skipping-instruction, and asking it to recheck is confirmation framing.
The resolution never required talking to the seat:
Availability is a property of the moment, not of the vendor: the same model has joined and delivered one hour and failed to join the next, on the same host with the same tooling. A rule that can be broken by the clock gets quietly ignored rather than obeyed, so the requirement is ordinal, never a headcount.
The property: no two seats whose agreement is load-bearing may share a model family, and the cold seat must not share a family with whoever wrote the change.
Degrade in this order, most expendable first: panel-internal separation, then cold-versus-panel separation, and never cold-versus-author.
The floor is a refusal, not a degradation. A cold read whose seat shares a family with the author is not a cold read and must not be recorded as one. Below the floor the review does not run and says so, because a silently-degraded panel is precisely a fallback: it returns a verdict shaped like a full one.
Name a collision mechanically, never apologetically. Not "vendors were short so this may be weaker", which a reader cannot act on. Instead: "seats X and Y are both family F, so any finding they agree on is one observation and not two, and the class left uncovered is what only a different family would have framed."
git ls-remote origin refs/pull/<n>/head, then positive-control the object with git cat-file -t.
Use a known-missing full-width object id as the negative control, for example forty zeroes. Do not
append a character to a valid object id: Git accepts an overlong hex string when its leading full
object id resolves, so that apparent negative can return the original object and pass falsely.
Fetch the exact ref first if that object is not local. When a PR exists, cross-check with
gh pr view <n> --json headRefOid rather than treating it as authority: a head field can lag after
a push, while a mergeability field may be answering a different strategy question. A branch-only
lane has no PR API cross-check; gh pr view <branch> may select an old closed PR and is not a
substitute. If two instruments disagree, reproduce the exact question each asks before calling
either one stale. Re-resolve the ref when you grade and again if you act.<sha>, read
<time>". A ref name is not an identifier.Stated plainly, because a norm presented as a control is the false assurance this whole discipline exists to prevent:
There is no artifact proving a brief was clean. That is why the briefer, and not the seat, is the party this file addresses.
Worth it: security-sensitive surfaces, hard-to-reverse changes, anything where the panel converged fast, anything you wrote yourself, and any change to the rules by which other work is graded.
Not worth it: a typo, a version bump, a change whose entire surface one reviewer can hold.
The cold seat is a second axis, not a fourth panelist: it does not substitute for panel breadth and panel breadth does not substitute for it.
© Cotal-AI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/cold-review of Cotal-AI/Cotal.
Open the folder on GitHubat commit a64403e
Cold Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cold Review this skillCotal-AI/Cotal | 322 | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| MCP Server Builderanthropics/skills | 180k | 63 repos | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| MCP Server BuildershareAI-lab/learn-claude-code | 78k | 4 repos | ~1.2k | Automated safety check: Pass | MIT | |
| MCP Integration for Pluginsanthropics/claude-plugins-official | 38k | 11 repos | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| MemPalace Memory SearchMemPalace/mempalace | 60k | — | ~1.4k | Automated safety check: Pass | MIT | |
| Crush Configurationcharmbracelet/crush | 29k | — | ~3.7k | Automated safety check: Pass | Custom licence |
anthropics/skills
Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.
shareAI-lab/learn-claude-code
Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.
anthropics/claude-plugins-official
Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.
MemPalace/mempalace
Mines project files and conversation exports into a local, searchable memory palace and recalls past work by semantic search through the mempalace CLI.
charmbracelet/crush
Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.
mksglu/context-mode
Routes large command, file, API and browser output through context-mode tools so only the needed result enters the agent's context, instead of dumping it via Bash.
Cotal-AI/Cotal
Set up Cotal on this machine: install it, start a local agent mesh (NATS + JetStream), verify it, and put an agent on it.
Cotal-AI/Cotal
Create or improve a 32×32 pixel-art persona face for the Frontier Faces demo (examples/04-frontier-faces/personas.mjs) — the animated agent avatars rendered by face-term.mjs / the browser…
Cotal-AI/Cotal
Define a multi-agent team for ANY task on ANY system as an explicit deployment topology - pick the shape from the task's dominant risk, specify the runtime/communication/trust layers, place model…
Cotal-AI/Cotal
Run several independent Cotal features concurrently by creating one Git worktree and one spawn-capable mesh manager per feature; each manager staffs a review panel in a dedicated channel, adds one…
Works with
Categories
Write the brief for a single independent cold reviewer and grade what it returns, keeping it isolated from the panel that already graded the change. Cold Review is an agent skill from Cotal-AI/Cotal. Write the brief for a single independent cold reviewer and grade what it returns, keeping it isolated from the panel that already graded the change.
Cold Review fits situations like: A panel has reached consensus and you want a second opinion consensus cannot anchor; A change is security-sensitive; hard to reverse; you are the author and therefore the worst available reader of your own work.
Run `npx skills add Cotal-AI/Cotal --skill cold-review -a claude-code`. Or copy the skill folder (.claude/skills/cold-review in Cotal-AI/Cotal) into .claude/skills/cold-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Cotal-AI/Cotal --skill cold-review -a codex`. Or copy the skill folder (.claude/skills/cold-review in Cotal-AI/Cotal) into .agents/skills/cold-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Cotal-AI/Cotal --skill cold-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cold-review, .gemini/skills/cold-review, .github/skills/cold-review and .opencode/skills/cold-review in your project.
Going by SKILL.md and its folder, Cold Review needs the command-line tools its instructions call (git and gh).
SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Cold Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Cold Review: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars) and MemPalace Memory Search (MemPalace/mempalace, 60k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Cotal-AI (a GitHub organization) maintains it in Cotal-AI/Cotal, which has 322 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 11, 2026.
Source: Cotal-AI/Cotal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.