Official agent skill

MCP Release QA

by github in github/awesome-copilot

Verify an MCP server before release by exercising a real protocol session, comparing runtime capabilities with source and documentation, testing failure paths, and recording reproducible evidence.

OfficialMITAuto-check passedAgent Workflows

Install MCP Release QA

skills CLI
$ npx skills add github/awesome-copilot --skill mcp-release-qa -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/awesome-copilot mcp-release-qa --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/mcp-release-qa .claude/skills/mcp-release-qa && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mcp-release-qa
GitHub stars
40k
Token cost
~1.8k tokens
SKILL.md length
833 words
Files
1
Skills in repo
417
Repo updated
First seen
Licence
MIT

At a glance

Verify an MCP server before release by exercising a real protocol session, comparing runtime capabilities with source and documentation, testing failure paths, and recording reproducible evidence.

  • Works in 8 steps: Establish the release surface → Start a clean server → Exercise one complete session → …
  • Reviewing an MCP server
  • SKILL.md covers Rules, 1. Establish the release surface, 2. Start a clean server and 3. Exercise one complete session, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

MCP Release QA is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Verify an MCP server before release by exercising a real protocol session, comparing runtime capabilities with source and documentation, testing failure paths, and recording reproducible evidence. Use when shipping or reviewing an MCP server, tool, resource, prompt, catalog, or install path.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering MCP servers. It works with Model Context Protocol. The repository describes itself as: Community-contributed instructions, agents, skills, and configurations to help you make the most of GitHub Copilot. The licence is MIT.

When your agent uses it

  • Reviewing an MCP server
  • Tasks that involve MCP servers

Example prompts

  • “/mcp-release-qa”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Establish the release surface
  2. Start a clean server
  3. Exercise one complete session
  4. Prove inventory parity
  5. Check published contracts
  6. Test failure paths
  7. Smoke-test installation
  8. Report the evidence

What it can do on your machine

Read from SKILL.md and the folder at commit 727ff2e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

MCP Release QA loads about 1.8k tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 833 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~77
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/awesome-copilot at commit 727ff2e, republished under its MIT licence (© github). 833 words, ~1,796 tokens.

Download SKILL.mdSave it as .claude/skills/mcp-release-qa/SKILL.md (or your agent's skills folder).
name
mcp-release-qa
description
Verify an MCP server before release by exercising a real protocol session, comparing runtime capabilities with source and documentation, testing failure paths, and recording reproducible evidence. Use when shipping or reviewing an MCP server, tool, resource, prompt, catalog, or install path.

MCP Release QA

Test the server that users will run. A schema review or a passing unit test is not runtime evidence.

This skill complements security review. It focuses on protocol behavior, published-contract drift, transport correctness, and reproducible release evidence.

Rules

  • Run checks against a fresh server process built from the candidate revision.
  • Keep initialize, notifications/initialized, discovery, and invocation in the same session. A new process is a new STDIO session.
  • Treat source registrations as implementation truth and public documentation as a contract that must match it.
  • Record exact commands and raw responses. Do not replace missing evidence with "looks correct."
  • Do not invoke mutation-capable tools against production data. Use fixtures, a sandbox, or stop and name the missing safe test environment.
  • Derive the expected capability inventory from the candidate source on every run.

1. Establish the release surface

Identify:

  • candidate commit and build command;
  • server entry point and transport: STDIO, Streamable HTTP, or SSE;
  • supported MCP protocol versions;
  • source files that register tools, resources, resource templates, and prompts;
  • generated catalogs, manifests, README tables, and install instructions;
  • existing protocol, integration, and smoke-test commands.

Prefer repository-native commands. Inspect package.json, pyproject.toml, Makefile, CI workflows, and contributor instructions before inventing a test harness.

2. Start a clean server

Build the candidate and start the documented entry point with test-safe configuration. Capture:

  • the exact command;
  • commit SHA;
  • environment variable names, with values redacted;
  • stdout, stderr, and exit status;
  • the endpoint or child-process transport used by the client.

For STDIO, stdout is protocol-only. Logs, banners, and stack traces belong on stderr. For HTTP transports, record the status, relevant MCP headers, and session identifier handling without printing credentials.

If the server cannot start from its documented instructions, report that as a release failure and preserve the startup error verbatim.

3. Exercise one complete session

Run this sequence through a real MCP client or the repository's integration harness:

  1. initialize with a protocol version the server claims to support.
  2. Confirm the negotiated version and advertised capabilities.
  3. Send notifications/initialized.
  4. Call ping.
  5. Call each supported discovery method:
    • tools/list
    • resources/list
    • resources/templates/list
    • prompts/list
  6. Exercise at least one representative read-only item from every advertised capability class.
  7. Follow pagination until no cursor remains when a list method is paginated.

Do not send post-initialization requests through separate one-shot processes. That accidentally tests several incomplete sessions instead of one valid session.

4. Prove inventory parity

Build four inventories from current evidence:

SurfaceEvidence
SourceRegistered tool, resource, template, and prompt definitions
RuntimeResults from the live discovery methods
Generated metadataCatalogs, manifests, or generated indexes
DocumentationREADME, reference pages, and install output

Compare by stable identifier. Report:

  • source entries missing at runtime;
  • runtime entries absent from metadata or documentation;
  • stale names, descriptions, arguments, URIs, or prompt parameters;
  • documented install commands that do not start the candidate server.

Regenerate derived files with the repository's own build command, then fail if the working tree still contains unexplained generated changes.

5. Check published contracts

For every discovered item, verify the runtime definition against its source:

Show full SKILL.md (330 more words)Show less
Tools
  • Name and description are stable and specific.
  • inputSchema defines types, required fields, enums, and bounds where needed.
  • Unknown properties are rejected when the tool contract is closed.
  • Mutation, idempotence, read-only, and open-world annotations match behavior.
  • Successful calls conform to outputSchema when one is published.
  • Errors are protocol errors or structured tool failures, not leaked stack traces.
Resources and templates
  • URIs and MIME types match the registered definitions.
  • Static resources are readable.
  • Template parameters are validated before resolution.
  • Missing or forbidden resources fail explicitly.
Prompts
  • Required and optional arguments match discovery output.
  • prompts/get returns usable messages for valid arguments.
  • Missing required arguments and unknown prompt names fail explicitly.

6. Test failure paths

At minimum, probe:

  • a request before initialization completes;
  • malformed JSON or an invalid JSON-RPC envelope;
  • an unknown method;
  • an unsupported protocol version;
  • repeated initialization;
  • unknown tool, resource, and prompt names;
  • missing, extra, wrong-type, and out-of-bounds arguments;
  • a request at the documented transport-size limit and one beyond it;
  • a controlled internal failure with credentials and stack traces redacted.

Verify that each response has the correct request ID, a useful error message, and no successful side effect. For STDIO, also confirm every stdout line is a complete protocol message and a healthy session leaves stderr clean unless the server explicitly documents diagnostic output.

7. Smoke-test installation

When the project publishes an install command:

  1. Create a temporary destination outside the source checkout.
  2. Run the public install command exactly as documented.
  3. Start the installed artifact without relying on files from the source tree.
  4. Repeat initialization, discovery, and one read-only invocation.
  5. Remove the temporary destination after preserving the command output.

An install string that was only inspected is unverified.

8. Report the evidence

Use this format:

markdown
# MCP Release QA

Candidate: [commit]
Transport: [STDIO | Streamable HTTP | SSE]
Verdict: PASS | PASS WITH CAVEATS | FAIL

## Commands and results
- `[exact command]` — [exit status and result]

## Session transcript
- initialize: [result]
- discovery: [result]
- representative calls: [result]
- negative paths: [result]

## Parity
| Identifier | Source | Runtime | Metadata | Docs | Result |
|---|---|---|---|---|---|

## Findings
| Severity | Evidence | Impact | Narrowest fix |
|---|---|---|---|

## Missing evidence
- [check that could not run and why]

Use FAIL for a server that cannot start, complete a valid session, keep the transport parseable, or safely reject invalid input. Use PASS WITH CAVEATS only for bounded documentation or metadata drift that does not misrepresent a dangerous capability. Otherwise use PASS.

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/mcp-release-qa of github/awesome-copilot.

Open the folder on GitHubat commit 727ff2e

Compare with similar skills

MCP Release QA next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

MCP Release QA compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
MCP Release QA this skillgithub/awesome-copilot40k—~1.8kAutomated safety check: PassMIT
Agent QA Authoringvostride/agent-qa902—~569Automated safety check: PassCustom licence
Agent QA Result Triagevostride/agent-qa902—~394Automated safety check: PassCustom licence
Lightpandalightpanda-io/agent-skill101—~6kAutomated safety check: PassApache-2.0
Opik Comparecomet-ml/opik-mcp219—~2.6kAutomated safety check: NotesApache-2.0
Agent QA Debug Fixvostride/agent-qa902—~398Automated safety check: PassCustom licence

Similar skills

  • Agent QA Authoring

    vostride/agent-qa

    A skill your agent uses when creating, editing, validating, or running agent-qa tests, suites, or hooks.

    902 GitHub stars~569 tokensUpdated 2 mo ago
    Agent WorkflowsAuto-check passed
  • Agent QA Result Triage

    vostride/agent-qa

    A skill your agent uses when investigating failed agent-qa runs, inspecting artifacts, classifying failures, or comparing recent runs.

    902 GitHub stars~394 tokensUpdated 2 mo ago
    Agent WorkflowsAuto-check passed
  • Lightpanda

    lightpanda-io/agent-skill

    Lightpanda browser, drop-in replacement for Chrome-based browsing in any AI agent - faster and lighter for tasks without graphical rendering like data retrieval.

    101 GitHub stars~6k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Opik Compare

    comet-ml/opik-mcp

    Run a candidate against the baseline over an Opik test suite and read the numbers back — which cases broke, which got fixed, the per-metric deltas, worst rows, and whether the two runs are…

    219 GitHub stars~2.6k tokensUpdated yesterday
    Agent WorkflowsAuto-check: notes
  • Agent QA Debug Fix

    vostride/agent-qa

    Use after an agent-qa run has failed and you need to debug, patch, and verify the issue using MCP evidence, logs, artifacts, and local code changes instead of generated fix suggestions.

    902 GitHub stars~398 tokensUpdated 2 mo ago
    Agent WorkflowsAuto-check passed
  • Unifi MCP Tool Builder

    enuno/unifi-mcp-server

    Specialized guide for adding new MCP tools to the UniFi MCP Server following project standards, UniFi API patterns, and test-driven development practices.

    281 GitHub stars~5.8k tokensUpdated 5 days ago
    Agent WorkflowsAuto-check passed

More from github/awesome-copilot

All 417 skills in this repo
  • Acquire Codebase Knowledge

    github/awesome-copilot

    Official

    Maps an unfamiliar codebase into seven evidence-backed documents in docs/codebase/, using a scan script and templates, for onboarding or architecture write-ups.

    40k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Draw.io Diagram Generator

    github/awesome-copilot

    Official

    Generates, edits and validates draw.io files with correct mxGraph XML, covering flowcharts, architecture, sequence, ER and UML class diagrams.

    40k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed
  • Credit Risk Data Cleaning

    github/awesome-copilot

    Official

    Cleans raw credit data and screens variables before loan modeling, dropping unstable, noisy or redundant features and writing an Excel report of every step.

    40k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Daily Focus Board

    github/awesome-copilot

    Official

    Builds a warm, browser-based daily focus board the user updates by talking to their agent, with Eisenhower priorities, a brain-dump box and kind not-today carryover.

    40k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Python Pypi Package Builder

    github/awesome-copilot

    Official

    End-to-end skill for building, testing, linting, versioning, and publishing a production-grade Python library to PyPI.

    40k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Questions about MCP Release QA

What does MCP Release QA do?

Verify an MCP server before release by exercising a real protocol session, comparing runtime capabilities with source and documentation, testing failure paths, and recording reproducible evidence. MCP Release QA is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Verify an MCP server before release by exercising a real protocol session, comparing runtime capabilities with source and documentation, testing failure paths, and recording reproducible evidence.

When should I use MCP Release QA?

MCP Release QA fits situations like: reviewing an MCP server; tasks that involve MCP servers.

How do I install MCP Release QA in Claude Code?

Run `npx skills add github/awesome-copilot --skill mcp-release-qa -a claude-code`. Or copy the skill folder (skills/mcp-release-qa in github/awesome-copilot) into .claude/skills/mcp-release-qa in your project. Claude Code loads it when a task matches its description.

How do I install MCP Release QA in Codex?

Run `npx skills add github/awesome-copilot --skill mcp-release-qa -a codex`. Or copy the skill folder (skills/mcp-release-qa in github/awesome-copilot) into .agents/skills/mcp-release-qa in your project. Codex loads it when a task matches its description.

Can I use MCP Release QA in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/awesome-copilot --skill mcp-release-qa -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mcp-release-qa, .gemini/skills/mcp-release-qa, .github/skills/mcp-release-qa and .opencode/skills/mcp-release-qa in your project.

What does MCP Release QA need to run?

SKILL.md names no scripts, command-line tools or credentials: MCP Release QA is instructions for the agent only.

Does MCP Release QA access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is MCP Release QA safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does MCP Release QA use?

MCP Release QA is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does MCP Release QA use?

About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to MCP Release QA?

Skills that share tags, products or a category with MCP Release QA: Agent QA Authoring (vostride/agent-qa, 902 stars), Agent QA Result Triage (vostride/agent-qa, 902 stars), Lightpanda (lightpanda-io/agent-skill, 101 stars) and Opik Compare (comet-ml/opik-mcp, 219 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains MCP Release QA?

github (a GitHub organization, an official publisher) maintains it in github/awesome-copilot, which has 39,748 GitHub stars. The repository holds 417 skills in this directory. The repository was last updated on October 7, 2026.

Source: github/awesome-copilot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.