Agent skill

Ax MCP

by dosco in dosco/aithy

This skill helps an LLM build correct native Model Context Protocol integrations with @ax-llm/ax.

Apache-2.0Auto-check passedAgent Workflows

Install Ax MCP

skills CLI
$ npx skills add dosco/aithy --skill ax-mcp -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dosco/aithy ax-mcp --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dosco/aithy.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/ax-mcp .claude/skills/ax-mcp && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ax-mcp
GitHub stars
107
Token cost
~4.4k tokens
SKILL.md length
1,762 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

This skill helps an LLM build correct native Model Context Protocol integrations with @ax-llm/ax.

  • The user asks about AxMCPClient
  • SKILL.md covers Non-Negotiable Rules, Choose A Transport, Protocol Eras and Attach MCP To AxGen, plus 11 more sections
  • Calls npm; needs MCP_ACCESS_TOKEN
  • Recording/replay

What it does

Ax MCP is an agent skill from dosco/aithy. This skill helps an LLM build correct native Model Context Protocol integrations with @ax-llm/ax. Use when the user asks about AxMCPClient, MCP transports, tools, prompts, resources, subscriptions, tasks, sampling, elicitation, roots, authentication, OAuth, MCP Apps, recording/replay, or MCP integration with AxGen, AxAgent, AxFlow, chat, optimization, and AxEventRuntime.

Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering MCP servers. It works with Model Context Protocol. The repository describes itself as: A personal AI agent that can work safely on your machine, remember useful context, and keep its data under your control. The licence is Apache-2.0.

When your agent uses it

  • The user asks about AxMCPClient
  • Recording/replay
  • MCP integration with AxGen

Example prompts

  • “/ax-mcp”

Requirements

  • A credential in MCP_ACCESS_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit 0c9855f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • MCP_ACCESS_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ax MCP loads about 4.4k tokens when it runs. Until then it costs about 95 tokens; SKILL.md has 1,762 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~95
When it runs · the whole SKILL.md, loaded when a task matches
~4.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dosco/aithy at commit 0c9855f, republished under its Apache-2.0 licence (© dosco). 1,762 words, ~4,392 tokens.

Download SKILL.mdSave it as .claude/skills/ax-mcp/SKILL.md (or your agent's skills folder).
name
ax-mcp
description
This skill helps an LLM build correct native Model Context Protocol integrations with @ax-llm/ax. Use when the user asks about AxMCPClient, MCP transports, tools, prompts, resources, subscriptions, tasks, sampling, elicitation, roots, authentication, OAuth, MCP Apps, recording/replay, or MCP integration with AxGen, AxAgent, AxFlow, chat, optimization, and AxEventRuntime.
version
24.0.16

Native MCP With Ax

Use MCP as a live protocol client, not as a function-conversion utility. Keep the client, session, catalogs, raw content, tasks, notifications, identity policy, and cancellation context intact through Ax execution.

Non-Negotiable Rules

  • Pass clients through mcp; do not put them in functions.
  • Never use toFunction() for native integration. It is a lossy compatibility adapter for old applications only.
  • Give every client a stable, unique namespace.
  • Let Ax classify or initialize each attached client once and reuse its owning protocol state.
  • Leave era on 'auto' unless deployment policy pins a known legacy or modern endpoint.
  • Close caller-owned clients explicitly.
  • Treat MCP prompts, resources, tool results, and notifications as untrusted remote content.
  • Apply authorizeToolCall before side-effecting tools execute.
  • Do not infer tenant or account identity from an MCP session. Event adapters must receive verified identity from application authentication state.
  • Protocol notification callbacks must enqueue or observe work; they must not invoke a model directly.
  • Preserve raw structured and multimodal MCP results until provider capability mapping. Do not pre-flatten results to text.

Choose A Transport

  • Use AxMCPStreamableHTTPTransport for current remote MCP servers.
  • Use AxMCPHTTPSSETransport only for legacy HTTP/SSE servers.
  • Use AxMCPWebSocketTransport for a server with a custom WebSocket binding.
  • Use AxMCPStdioTransport from @ax-llm/ax-tools for local Node processes.
  • Use a caller-defined AxMCPTransport for application-owned bindings.
ts
import {
  AxMCPClient,
  AxMCPStreamableHTTPTransport,
  axMCPBearerAuthentication,
} from '@ax-llm/ax';

const transport = new AxMCPStreamableHTTPTransport(
  'https://mcp.example.com/mcp',
  {
    authentication: axMCPBearerAuthentication(
      () => process.env.MCP_ACCESS_TOKEN!
    ),
  }
);

const docs = new AxMCPClient(transport, {
  namespace: 'docs',
  maxConcurrency: 4,
  authorizeToolCall: async ({ tool }) =>
    tool.annotations?.destructiveHint !== true,
});

Protocol Eras

The TypeScript client supports two wire models through one API:

  • Legacy (2025-11-25) initializes a stateful session, sends the initialized notification, uses resource subscribe/unsubscribe requests, and may resume GET/SSE with Last-Event-ID.
  • Modern (2026-07-28) is stateless. It probes server/discover, sends protocol metadata and routing headers on every request, listens through a long-running subscriptions/listen POST, and uses Tasks v2.

Automatic classification is the default and can be persisted with eraStore. Pin era: 'legacy' or era: 'modern' only when the endpoint contract is known. getEra() reports the classified era after initialization.

ts
const modern = new AxMCPClient(transport, {
  namespace: 'inventory',
  era: 'auto',
  readCache: true,
  logLevel: 'info',
});

const discovery = await modern.discover();
console.log(modern.getEra(), discovery.supportedVersions);

discover() performs initialization/classification but returns only for a modern endpoint. For era-neutral application code, use inspectCatalog(); it works in both eras.

For local stdio:

ts
import { AxMCPClient } from '@ax-llm/ax';
import { AxMCPStdioTransport } from '@ax-llm/ax-tools';

const stdio = new AxMCPStdioTransport({
  command: 'node',
  args: ['./server.mjs'],
});
const local = new AxMCPClient(stdio, { namespace: 'local' });

AxMCPStdioTransport owns its child process. After local.close(), also call stdio.terminate() until the stdio transport exposes the common close() lifecycle directly.

Attach MCP To AxGen

Attach clients in constructor or forward options. Per-call options override instance defaults.

ts
const gen = ax('question:string -> answer:string', { mcp: docs });

const result = await gen.forward(llm, { question }, {
  mcpContext: [
    { client: 'docs', resource: { uri: 'docs://guide' } },
  ],
});

mcpContext resolves selected prompts or resources before the first model call and adds attributed, untrusted context. Native tool calls retain client identity and raw MCP results in memory. streamingForward() keeps Ax output streaming separate from MCP progress and task events.

Attach MCP To AxAgent

ts
const assistant = agent('query:string -> answer:string', {
  mcp: [docs, search],
  mcpInheritance: 'all',
  functionDiscovery: true,
  contextFields: [],
});

Agents expose native modules under mcp.<namespace>:

text
mcp.docs.tools.<tool>
mcp.docs.prompts.list()
mcp.docs.prompts.get(name, args)
mcp.docs.resources.list()
mcp.docs.resources.templates()
mcp.docs.resources.read(uri)
mcp.docs.resources.subscribe(uri)
mcp.docs.resources.unsubscribe(uri)
mcp.docs.tasks.get(taskId)
mcp.docs.tasks.cancel(taskId)
mcp.docs.complete(...)

RLM actor definitions and discovery use these exact runtime paths. MCP tools are callable as mcp.<namespace>.tools.<tool> and UCP operations as ucp.<namespace>.<operation>; neither protocol is exposed to the model as bare provider-native functions.

Modern modules also expose task input/update behavior through the client. tasks.list() and tasks.result() are legacy task-draft compatibility APIs and reject modern servers.

Use mcpInheritance: 'all', 'none', or a namespace allowlist. The resulting live execution context propagates through Agent stages, llmQuery, RLM, and child programs. Large catalogs participate in Agent discovery; do not copy their tools into an inline functions array.

AxFlow And High-Level Chat

Pass mcp in Flow defaults or forward options. Nested nodes inherit the same execution context unless mcpInheritance restricts it. Parallel nodes share the client while respecting its concurrency limit and abort signal.

Use axMCPChat(ai, request, { mcp }) for a high-level non-streaming native MCP tool loop. Do not build a second ad-hoc tool dispatcher around ai.chat().

Catalogs And Raw Operations

An endpoint is only the server address. The server owns tool names, prompt names, resource names, resource URIs, and URI templates. Discover one cloned snapshot before asking users to configure identifiers:

ts
const catalog = await docs.inspectCatalog();

console.log(catalog.tools);
console.log(catalog.prompts);
console.log(catalog.resources);
console.log(catalog.resourceTemplates);

const prompt = await docs.getPrompt('review', { topic: 'MCP' });
const resource = await docs.readResource('docs://guide');
const completion = await docs.complete(reference, argument);

inspectCatalog({ refresh: true }) forces fresh bounded pagination. Snapshot mutation cannot change the live client. List-change notifications refresh the catalog revision, and native Ax model steps rebuild tool definitions when that revision changes. Concrete resources can be selected immediately. URI templates are discoverable but never expanded automatically; applications construct an authorized concrete URI and may use MCP completion to suggest argument values.

Multi Round-Trip Requests

Modern tool calls, prompt reads, and resource reads may return resultType: 'input_required'. Ax fulfills the embedded roots, sampling, or elicitation requests through the same host handlers used by legacy server requests, then repeats the original operation with the latest input responses and byte-exact requestState.

The generated Python, Java, C++, Go, and Rust clients fulfill roots and host-callback elicitation in modern MRTR rounds. They advertise elicitation only when a real handler is installed, never advertise sampling, and reject a truthy sampling option during initialization. Legacy inbound elicitation and MRTR sampling remain TypeScript-only.

Configure only handlers the host can enforce. Ax limits the loop to five input rounds by default; use maxInputRounds for a stricter policy. A missing handler or exhausted round limit is a protocol error. The tool concurrency slot stays held throughout all rounds.

Tasks, Progress, And Cancellation

Modern Tasks v2 are server-directed. callTool() auto-awaits an unsolicited task by default, so Ax tool bindings keep returning the final tool result. Use callToolOutcome() or taskHandling: 'expose' when the application needs the task handle, and answer input_required work with provideTaskInput():

ts
const outcome = await docs.callToolOutcome('reindex', { scope: 'all' });
if (outcome.kind === 'task') {
  const task = await docs.getTask(outcome.task.taskId);
  if (task.status === 'input_required') {
    await docs.provideTaskInput(task.taskId, {
      approval: { action: 'accept', content: { approved: true } },
    });
  }
  if (task.status === 'working') await docs.cancelTask(task.taskId);
}

Use subscribeTaskStatus or subscribeEvents for observation. Keep polling available because task notifications are optional. Pass Ax abort signals through program execution; never blindly replay a tool call after an uncertain post-side-effect failure.

callToolTask(), listTasks(), and getTaskResult() remain functional only for legacy task-draft servers and are deprecated. Modern completed results and errors are embedded in tasks/get.

Subscriptions And Event-Driven Agents

Use AxMCPEventSource with AxEventRuntime. A subscription callback only publishes an event into the inbox. Explicit routes decide whether to observe, invalidate, wake, or resume.

ts
const source = new AxMCPEventSource({
  client: docs,
  resourceSubscriptions: {
    select: (resource) =>
      resource.mimeType === 'text/markdown' &&
      resource.name === 'Engineering guide',
  },
  identity: { tenantId: 'tenant-1' },
  trust: 'authenticated',
});

const runtime = eventRuntime({
  allowVolatile: true,
  sources: [source],
  routes: [
    ...axMCPEventRoutes({ client: docs }),
    eventRoute('guide-updated')
      .types('mcp.resource.updated')
      .authenticated()
      .wake(
        eventTarget('reviewer')
          .program(reviewer)
          .ai(llm)
          .input((input) =>
            input.field('uri', eventPath.data('uri'))
          )
          .build()
      )
      .build(),
  ],
});

Safe defaults are:

  • omitted resource policy -> subscribe to no resources
  • 'all' -> explicitly subscribe to all discovered concrete resources
  • URI array -> explicitly subscribe to application-constructed concrete URIs
  • selector -> choose concrete resources by name, URI, description, MIME type, annotations, or the surrounding catalog
  • catalog changes -> invalidate
  • progress and logging -> observe
  • resource updates -> no implicit wake
  • input_required and terminal task states -> resume the owning continuation

The signature-aware input plan is the data boundary. Raw event data remains in eventContext; only fields selected with segment-safe eventPath descriptors become program inputs. Use multiple matching routes to fan one notification out to multiple Agents with independent authorization and run records.

Managed sources refresh and diff their selection after notifications/resources/list_changed. They keep the prior selection if a selector throws, retain successful wire transitions after a partial failure, and retry incomplete work on the next change or reconnect. The client tracks a separate logical owner for manual subscriptions, every source, and restored intent: only the first owner sends resources/subscribe, and only the last release sends resources/unsubscribe. Closing a source cannot break another owner. Closing the client terminates all ownership and transport state.

Listening is era-aware. Legacy clients maintain resource subscriptions with resources/subscribe and resume a GET/SSE stream with Last-Event-ID when the server supports it. Modern clients place catalog interests, concrete resource URIs, and known task IDs in subscriptions/listen; changes restart that POST stream with a fresh request ID and no resume header. In both eras, startListening() is nonblocking and returns a handle with ready, done, and close().

For the detailed lifecycle and troubleshooting guide, read docs/MCP_SUBSCRIPTIONS.md and use the checked-in six-language MCP examples.

Show full SKILL.md (573 more words)Show less

Server-Initiated Requests

Configure handlers on AxMCPClient when advertising the corresponding client capability:

  • sampling for sampling/createMessage
  • elicitation for form or URL elicitation
  • roots for roots/list
  • onProgress, onLoggingMessage, and onTaskStatus for observation

Do not advertise a client capability without a working host handler and policy.

Authentication And OAuth

For simple authentication, compose axMCPBearerAuthentication, axMCPBasicAuthentication, axMCPAPIKeyAuthentication, axMCPHMACAuthentication, or a caller-defined strategy in the HTTP transport.

Use the transport oauth option for protected-resource discovery, PKCE, client metadata or dynamic registration, refresh, challenge-driven scope step-up, DPoP, PAR/JAR/RAR, mTLS, revocation, introspection, client credentials, or enterprise-managed authorization. Supply persistent token and registration stores in distributed deployments. Never serialize tokens into Ax program or event state.

Generated Python, Java, C++, Go, and Rust transports implement the portable OAuth middle tier: RFC 9728 well-known and challenge discovery, RFC 8414/OIDC authorization-server metadata, PKCE S256 authorization-code exchange, RFC 8707 resource binding, refresh with a 60-second skew, client credentials, and RFC 9207 iss. Configure the language's AxMCPOAuthOptions with clientId, an endpoint-keyed tokenStore, onAuthCode, and requireIss. The host callback receives an authorization URL and returns code, state, and iss; it owns browser or headless interaction. none and client_secret_post are the only generated-port client authentication modes.

Do not suggest TypeScript-only DPoP, CIMD/DCR, JAR, PAR, RAR, mTLS, revocation/introspection, JWT validation, or enterprise-managed authorization for a generated-language client. Use npm run test:mcp-oauth as the credential-free cross-language gate. See docs/MCP_UCP.md for compact per-language configuration snippets.

Keep SSRF protection enabled for remote discovery and redirect handling. Relax loopback or HTTP restrictions only for controlled local development.

For checked-in Streamable HTTP examples, set AX_MCP_ENDPOINT. A localhost TypeScript demo must opt in explicitly with ssrfProtection: { allowHTTP: true, allowLoopback: true }; never copy that configuration to a remote endpoint. Generated examples use their equivalent requireHttps / allowLocalhost / allowPrivateNetworks fields only for 127.0.0.1.

For a real local check, run src/examples/mcp-event-demo-server.ts, set AX_MCP_ENDPOINT=http://127.0.0.1:3001/mcp, and trigger /control/resource or /control/task/complete. The mandatory credential-free matrix is npm run test:mcp-events:generated; provider-backed examples are advisory and require their documented API key.

MCP Apps And Extensions

Negotiate official extensions through client capabilities. Use AxMCPAppBridge for MCP App resources and host messages; enforce CSP, permissions, visibility, allowed tools, and untrusted model-context policy. Do not render arbitrary HTML returned from a normal tool result as an MCP App.

Recording, Replay, And Evaluation

Wrap a real transport with AxMCPRecordingTransport to capture deterministic protocol interactions. Use AxMCPReplayTransport for tests, optimization, and evaluation. Live MCP evaluation is rejected by default because repeated model runs could repeat external side effects; opt in only deliberately.

Testing Checklist

  • Use a local deterministic protocol server or replay transport.
  • Assert namespace and tool collisions fail before model execution.
  • Test raw text, image, audio, resource-link, embedded-resource, metadata, task, and error results.
  • Test catalog changes during a multi-step run.
  • Test authorization denial before transport execution.
  • Test subscription reconnect and logical resubscription.
  • Test anonymous events cannot match authenticated routes.
  • Test terminal task events resume only the owning identity and correlation.
  • Test cancellation and uncertain outcomes without duplicate side effects.
  • Close clients, listening handles, runtimes, and local servers in finally.

Generated transports currently supervise legacy long-lived GET/SSE connections and resume with Last-Event-ID when available. Generated event runtimes remain host-driven: schedule delayed work with nextDueAt() and runDue(). Rust hosts also call AxMCPEventSource.poll() to drain protocol callbacks on the host thread. Close the source/runtime before the caller-owned client so unsubscribe and cancellation messages can still be sent.

For generic inbox, continuation, store, and sink behavior, use the ax-event-runtime skill. For program-specific behavior, combine this skill with ax-gen, ax-agent, or ax-flow.

© dosco, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/ax-mcp of dosco/aithy.

Open the folder on GitHubat commit 0c9855f

Compare with similar skills

Ax MCP next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ax MCP compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ax MCP this skilldosco/aithy107—~4.4kAutomated safety check: PassApache-2.0
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0
MCP Server Builder with mcp-usemcp-use/mcp-use11k—~923Automated safety check: PassApache-2.0
Agents SDKcloudflare/skills3k2 repos~3kAutomated safety check: PassApache-2.0

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Builds, modifies, debugs, migrates and verifies TypeScript MCP servers and MCP Apps with the mcp-use framework, treating the installed package's types as the source of truth.

    11k GitHub stars~923 tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Agents SDK

    cloudflare/skills

    Official

    Build, debug, or review Cloudflare Agents SDK applications using the agents package.

    3k GitHub starsUsed in 2 repos~3k tokens
    Agent WorkflowsAuto-check passed
  • Cao MCP Apps

    awslabs/cli-agent-orchestrator

    Official

    Enable, operate, and extend CAO's MCP Apps surface — the host-rendered fleet dashboard visible inside MCP App hosts (Claude Desktop, ChatGPT, VS Code Copilot, Goose, Postman).

    1.4k GitHub stars~1.9k tokensUpdated today
    Agent WorkflowsAuto-check passed

More from dosco/aithy

All 17 skills in this repo
  • This skill helps an LLM generate correct AxAgent observability code using @ax-llm/ax.

    107 GitHub stars~4.4k tokensUpdated 1 mo ago
    Auto-check passed
  • This skill helps an LLM generate correct AxAgent tuning and evaluation code using @ax-llm/ax.

    107 GitHub stars~4.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Ax Audio

    dosco/aithy

    This skill helps an LLM generate correct audio code with @ax-llm/ax.

    107 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Ax Gepa

    dosco/aithy

    This skill helps an LLM generate correct AxGEPA optimization code using @ax-llm/ax.

    107 GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Ax LLM

    dosco/aithy

    This skill helps with using the @ax-llm/ax TypeScript library for building LLM applications.

    107 GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Ax Playbook

    dosco/aithy

    This skill helps an LLM generate correct playbook code using @ax-llm/ax.

    107 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Ax MCP

What does Ax MCP do?

This skill helps an LLM build correct native Model Context Protocol integrations with @ax-llm/ax. Ax MCP is an agent skill from dosco/aithy. This skill helps an LLM build correct native Model Context Protocol integrations with @ax-llm/ax.

When should I use Ax MCP?

Ax MCP fits situations like: the user asks about AxMCPClient; recording/replay; MCP integration with AxGen.

How do I install Ax MCP in Claude Code?

Run `npx skills add dosco/aithy --skill ax-mcp -a claude-code`. Or copy the skill folder (.claude/skills/ax-mcp in dosco/aithy) into .claude/skills/ax-mcp in your project. Claude Code loads it when a task matches its description.

How do I install Ax MCP in Codex?

Run `npx skills add dosco/aithy --skill ax-mcp -a codex`. Or copy the skill folder (.claude/skills/ax-mcp in dosco/aithy) into .agents/skills/ax-mcp in your project. Codex loads it when a task matches its description.

Can I use Ax MCP in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dosco/aithy --skill ax-mcp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ax-mcp, .gemini/skills/ax-mcp, .github/skills/ax-mcp and .opencode/skills/ax-mcp in your project.

What does Ax MCP need to run?

Going by SKILL.md and its folder, Ax MCP needs the command-line tools its instructions call (npm) and credentials named MCP_ACCESS_TOKEN. Our summary lists: A credential in MCP_ACCESS_TOKEN.

Does Ax MCP access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ax MCP safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ax MCP use?

Ax MCP is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ax MCP use?

About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ax MCP?

Skills that share tags, products or a category with Ax MCP: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars) and MCP Server Builder with mcp-use (mcp-use/mcp-use, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ax MCP?

dosco (a GitHub user) maintains it in dosco/aithy, which has 107 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on August 31, 2026.

Source: dosco/aithy on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.