Agent skill

Add MCP From Catalog

by speakeasy-api in speakeasy-api/gram

Add a reviewed MCP Catalogue server to an explicit AICP project through the Speakeasy AI Control Plane Platform MCP.

AGPL-3.0Auto-check passedAgent Workflows

Install Add MCP From Catalog

skills CLI
$ npx skills add speakeasy-api/gram --skill add-mcp-from-catalog -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install speakeasy-api/gram add-mcp-from-catalog --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/speakeasy-api/gram.git skills-src && mkdir -p .claude/skills && cp -r skills-src/server/internal/plugins/platform_mcp_skills/add-mcp-from-catalog .claude/skills/add-mcp-from-catalog && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
add-mcp-from-catalog
GitHub stars
273
Token cost
~2.2k tokens
SKILL.md length
1,320 words
Files
1
Skills in repo
40
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Add a reviewed MCP Catalogue server to an explicit AICP project through the Speakeasy AI Control Plane Platform MCP.

  • Works in 11 steps: Call list_projects to verify that the… → Call search_mcp_catalog. Present the… → Call inspect_mcp_candidate for the… → …
  • Tasks that involve MCP servers
  • SKILL.md covers Safety rules and Workflow
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Add MCP From Catalog is an agent skill from speakeasy-api/gram. Add a reviewed MCP Catalogue server to an explicit AICP project through the Speakeasy AI Control Plane Platform MCP.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering MCP servers. It works with Model Context Protocol. The repository describes itself as: Securely scale AI usage across your organization. A single stack to Connect, Secure, Observe and Distribute agents, MCPs, and Skills within your company. The licence is AGPL-3.0.

When your agent uses it

  • Tasks that involve MCP servers

Example prompts

  • “/add-mcp-from-catalog”

Workflow steps

11 steps, taken from the first numbered list in SKILL.md.

  1. Call list_projects to verify that the Platform MCP is authenticated and obtain the eligible projects. If authenticated discovery is…
  2. Call search_mcp_catalog. Present the eligible projects and reviewed candidates, then ask the user to choose one exact candidate and one…
  3. Call inspect_mcp_candidate for the selected candidate. Explain the bounded change and collect only the non-secret configuration fields…
  4. If the user chose a new project and still wants this candidate after inspection, agree the project's exact name and choose one idempotency…
  5. Call get_mcp_readiness with the returned project and registration ID to inspect persisted readiness.
  6. Route secure setup from the exact readiness evidence
  7. After the user completes any secure handoff, branch by caller surface
  8. When readiness is current and ready, report the server-returned evidence. Registration is still private at this point: an MCP takes effect…
  9. Call get_mcp_client_admission for the same project and registration ID and report the mode it returns together with the custom client ID…
  10. Call list_plugins for the selected project, present the plugins it returns, and ask the user which one should carry this MCP. Do not…
  11. After the user names a plugin, call distribute_mcp_to_plugin with that exact plugin. A name matching nothing is refused as not_found and a…

What it can do on your machine

Read from SKILL.md and the folder at commit b4c4904. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Add MCP From Catalog loads about 2.2k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 1,320 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from speakeasy-api/gram at commit b4c4904, republished under its AGPL-3.0 licence (© speakeasy-api). 1,320 words, ~2,184 tokens.

Download SKILL.mdSave it as .claude/skills/add-mcp-from-catalog/SKILL.md (or your agent's skills folder).
name
add-mcp-from-catalog
description
Add a reviewed MCP Catalogue server to an explicit AICP project through the Speakeasy AI Control Plane Platform MCP.

Add an MCP from the catalog

Use this workflow only through the authenticated Speakeasy AI Control Plane (AICP) Platform MCP. It follows the same guarded outcome a user would complete manually in the AICP dashboard: select a reviewed MCP, configure it for an explicit project, finish secure setup, and verify readiness. The package itself grants no organization access.

If the user instead supplies a remote MCP URL outside the reviewed catalogue, use the add-mcp-from-remote-url workflow.

Safety rules

  • Never ask the user to paste API keys, passwords, access or refresh tokens, OAuth codes, client secrets, secret headers, or MCP credentials into chat.
  • Never ask the user to supply an MCP endpoint. Use the server-owned catalog candidate and registration workflow.
  • Show non-secret provider and setup URLs only when a Platform MCP tool returns them.
  • Keep the chosen project and catalog candidate explicit. Do not infer either from a previous conversation or silently substitute another target.
  • Registration is private and does not distribute or publish the MCP.
  • Use send_platform_mcp_feedback only after asking for consent, and never include identifiers, URLs, credentials, payloads, headers, logs, or attachments.

Workflow

  1. Call list_projects to verify that the Platform MCP is authenticated and obtain the eligible projects. If authenticated discovery is unavailable, stop and ask the user to complete or repair AICP OAuth; do not claim that installation succeeded.
  2. Call search_mcp_catalog. Present the eligible projects and reviewed candidates, then ask the user to choose one exact candidate and one exact project. Only when create_project is in your tool list may you also offer a new project if no listed project fits, or none exists yet; do not create it yet. A managed project assistant has no create_project tool and always registers in its own project, so never offer it there.
  3. Call inspect_mcp_candidate for the selected candidate. Explain the bounded change and collect only the non-secret configuration fields declared by that result.
  4. If the user chose a new project and still wants this candidate after inspection, agree the project's exact name and choose one idempotency key for this create; pass that same key on the preview and on the confirmed call. Call create_project with that name, that key, and confirmed: false to preview it: nothing is created, and the confirmation_required result returns the exact slug the project would get. Do not work the slug out yourself. Show that slug to the user as the project's permanent address in dashboard links; it does not change on rename. After the user confirms the name and slug, call create_project again with the same name, the same key, and confirmed: true. Use the project it returns; it starts empty. Use a fresh key only for a new attempt after a refusal. A conflict refusal means a project already holds that slug and nothing was created: offer that existing project or a different name. Creating a project needs organization administrator access; if it is refused, say so rather than choosing another project. Then, after explicit confirmation of the exact project, candidate, and configuration, call register_catalog_mcp with the exact selected project, reviewed candidate, declared non-secret configuration, and a fresh idempotency key. Do not distribute it.
  5. Call get_mcp_readiness with the returned project and registration ID to inspect persisted readiness.
  6. Route secure setup from the exact readiness evidence:
    • For upstream_identity_provider_not_configured, explain that AICP can attach the one identity provider discovered from the persisted reviewed MCP source. Ask for explicit confirmation, then call attach_platform_mcp_identity_provider, present its exact Inspect authorization URL, and wait for the user to use Connect or Authorize.
    • For upstream_authorization_required, call attach_platform_mcp_identity_provider again with confirmation to retrieve the current server-issued Inspect authorization URL. Present that exact clickable URL and wait for the user to use Connect or Authorize.
    • For any other secure dashboard setup result, present only its exact server-returned setup URL. The user completes OAuth or secret entry outside the agent. Never request the resulting code, token, or secret in chat.
  7. After the user completes any secure handoff, branch by caller surface:
    • For a connected external Platform MCP client, call get_mcp_readiness with force: true. Do not rely on stale or inferred readiness.
    • For a managed project assistant, call get_mcp_readiness without force and report only the persisted actor-scoped evidence. A forced provider probe stays with connected external clients; identity-provider attachment does not.
  8. When readiness is current and ready, report the server-returned evidence. Registration is still private at this point: an MCP takes effect only once a plugin carries it.
  9. Call get_mcp_client_admission for the same project and registration ID and report the mode it returns together with the custom client ID metadata URLs it lists, which together decide which MCP clients may authorize against this server. Change it only when the user asks: explain what the proposed mode admits and refuses, ask for explicit confirmation, then call set_mcp_client_admission with that exact mode and confirmed: true. Known clients (presets) refuses an unlisted client at authorization with no fallback, so confirm the user accepts that before selecting it. Custom client ID metadata URLs are still added from the MCP server's Authentication settings in the AICP dashboard.
  10. Call list_plugins for the selected project, present the plugins it returns, and ask the user which one should carry this MCP. Do not choose for them and do not assume the default plugin. Only when create_plugin is in your tool list may you offer a new plugin if no listed plugin fits. A managed project assistant has no create_plugin tool, so never offer or call it there: if no listed plugin fits, ask the user to create the plugin in the AICP dashboard or from an external MCP client, then call list_plugins again and continue with the plugin they created. If the user wants a new plugin and create_plugin is available, agree its name (and a slug only if they want to choose one), choose one idempotency key for this create, and call create_plugin for the selected project with that key and confirmed: false. Nothing is created and no receipt is stored; the confirmation_required refusal carries the exact slug the plugin would get. Show the user that slug as the plugin's permanent install name, which does not change on rename; never work a slug out yourself. Say that in the organization's default project a new plugin reaches every member, while elsewhere it reaches no one until people are assigned to it. After they confirm the name and slug, call create_plugin again with the same name, slug and description, the same idempotency key, and confirmed: true, and use the plugin it returns. If it refuses with slug_taken, another plugin already holds that slug: call list_plugins again, then ask whether to use that existing plugin or create one with a different slug, and preview and confirm the new slug as a new create, with a fresh idempotency key used for both its calls. If it refuses with idempotency_key_reused, the key was already spent on a different request: repeat the original request exactly with its original key, and use a new key only for a request the user has newly confirmed. If it refuses with feature_unavailable, creating a plugin is not available on this server: report that, stop creating, and do not retry or substitute another plugin. Instead ask the user to create the plugin in the AICP dashboard or from an external MCP client, then call list_plugins again and continue with the plugin they created. Never treat any of these refusals as having created a plugin.
  11. After the user names a plugin, call distribute_mcp_to_plugin with that exact plugin. A name matching nothing is refused as not_found and a name matching more than one as ambiguous_target; report the refusal and ask again rather than retrying with a different plugin, creating a plugin the user did not ask for, or distributing to another project.
Show full SKILL.md (23 more words)Show less

OAuth consent and approved secret entry are the expected out-of-agent stops. Project and catalog selection and identity-provider attachment confirmation stay in the conversation.

© speakeasy-api, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in server/internal/plugins/platform_mcp_skills/add-mcp-from-catalog of speakeasy-api/gram.

Open the folder on GitHubat commit b4c4904

Compare with similar skills

Add MCP From Catalog next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Add MCP From Catalog compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Add MCP From Catalog this skillspeakeasy-api/gram273—~2.2kAutomated safety check: PassAGPL-3.0
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k4 repos~1.2kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence
Context Mode Output Sandboxmksglu/context-mode26k—~4.1kAutomated safety check: PassCustom licence

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 4 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Context Mode Output Sandbox

    mksglu/context-mode

    Routes large command, file, API and browser output through context-mode tools so only the needed result enters the agent's context, instead of dumping it via Bash.

    26k GitHub stars~4.1k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Migrates the compatible subset of settings and global file-based MCP servers from the Warp desktop app into Warp Agent CLI without exposing credentials or state.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    Agent WorkflowsAuto-check passed

More from speakeasy-api/gram

All 40 skills in this repo
  • Gram Playwright CLI

    speakeasy-api/gram

    A skill your agent uses when automating the Speakeasy dashboard in a browser, capturing screenshots, inspecting pages.

    273 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Transactional Email

    speakeasy-api/gram

    A skill your agent uses when adding, changing, restyling, reviewing, validating, or previewing a Speakeasy transactional email, in Go or in LMX/MJML — a template<name.go, a TemplateKey constant, a…

    273 GitHub stars~4.7k tokensUpdated today
    Auto-check passed
  • Admin Shadcn

    speakeasy-api/gram

    A skill your agent uses when adding, changing, or styling UI in client/admin (the Speakeasy admin dashboard) that touches shadcn/ui — a button, dialog, table, sidebar, badge, select, tabs, tooltip…

    273 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • A skill your agent uses when adding, editing, reviewing, testing, or locating a reviewed skill distributed with the Platform MCP plugin; triggers include "Platform MCP skill", "platformmcpskills"…

    273 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Clickhouse

    speakeasy-api/gram

    A skill your agent uses when changing or reviewing Speakeasy ClickHouse schemas, migrations, queries, inserts, access principals, bootstrap SQL, Cloud compatibility, partial migration failures, or…

    273 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Feature Flag

    speakeasy-api/gram

    A skill your agent uses when gating a feature behind a flag, dogfooding or gradually rolling out a change, choosing between productfeatures and PostHog feature flags, adding or checking a product…

    273 GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Categories

Questions about Add MCP From Catalog

What does Add MCP From Catalog do?

Add a reviewed MCP Catalogue server to an explicit AICP project through the Speakeasy AI Control Plane Platform MCP. Add MCP From Catalog is an agent skill from speakeasy-api/gram. Add a reviewed MCP Catalogue server to an explicit AICP project through the Speakeasy AI Control Plane Platform MCP.

When should I use Add MCP From Catalog?

Add MCP From Catalog fits situations like: tasks that involve MCP servers.

How do I install Add MCP From Catalog in Claude Code?

Run `npx skills add speakeasy-api/gram --skill add-mcp-from-catalog -a claude-code`. Or copy the skill folder (server/internal/plugins/platform_mcp_skills/add-mcp-from-catalog in speakeasy-api/gram) into .claude/skills/add-mcp-from-catalog in your project. Claude Code loads it when a task matches its description.

How do I install Add MCP From Catalog in Codex?

Run `npx skills add speakeasy-api/gram --skill add-mcp-from-catalog -a codex`. Or copy the skill folder (server/internal/plugins/platform_mcp_skills/add-mcp-from-catalog in speakeasy-api/gram) into .agents/skills/add-mcp-from-catalog in your project. Codex loads it when a task matches its description.

Can I use Add MCP From Catalog in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add speakeasy-api/gram --skill add-mcp-from-catalog -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/add-mcp-from-catalog, .gemini/skills/add-mcp-from-catalog, .github/skills/add-mcp-from-catalog and .opencode/skills/add-mcp-from-catalog in your project.

What does Add MCP From Catalog need to run?

SKILL.md names no scripts, command-line tools or credentials: Add MCP From Catalog is instructions for the agent only.

Does Add MCP From Catalog access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Add MCP From Catalog safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Add MCP From Catalog use?

Add MCP From Catalog is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Add MCP From Catalog use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Add MCP From Catalog?

Skills that share tags, products or a category with Add MCP From Catalog: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars) and Crush Configuration (charmbracelet/crush, 29k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Add MCP From Catalog?

speakeasy-api (a GitHub organization) maintains it in speakeasy-api/gram, which has 273 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on October 10, 2026.

Source: speakeasy-api/gram on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.