Agent skill

Add MCP From Remote URL

by speakeasy-api in speakeasy-api/gram

Add a user-supplied remote MCP server URL to an explicit AICP project through the Speakeasy AI Control Plane Platform MCP.

AGPL-3.0Auto-check passedAgent Workflows

Install Add MCP From Remote URL

skills CLI
$ npx skills add speakeasy-api/gram --skill add-mcp-from-remote-url -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install speakeasy-api/gram add-mcp-from-remote-url --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/speakeasy-api/gram.git skills-src && mkdir -p .claude/skills && cp -r skills-src/server/internal/plugins/platform_mcp_skills/add-mcp-from-remote-url .claude/skills/add-mcp-from-remote-url && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
add-mcp-from-remote-url
GitHub stars
273
Token cost
~2k tokens
SKILL.md length
1,149 words
Files
1
Skills in repo
39
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Add a user-supplied remote MCP server URL to an explicit AICP project through the Speakeasy AI Control Plane Platform MCP.

  • Works in 11 steps: Call list_projects to verify that the… → If the user names a product that could… → Call inspect_mcp_candidate with… → …
  • Tasks that involve MCP servers
  • SKILL.md covers Safety rules and Workflow
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Add MCP From Remote URL is an agent skill from speakeasy-api/gram. Add a user-supplied remote MCP server URL to an explicit AICP project through the Speakeasy AI Control Plane Platform MCP.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering MCP servers. It works with Model Context Protocol. The repository describes itself as: Securely scale AI usage across your organization. A single stack to Connect, Secure, Observe and Distribute agents, MCPs, and Skills within your company. The licence is AGPL-3.0.

When your agent uses it

  • Tasks that involve MCP servers

Example prompts

  • “/add-mcp-from-remote-url”

Workflow steps

11 steps, taken from the first numbered list in SKILL.md.

  1. Call list_projects to verify that the Platform MCP is authenticated and obtain eligible projects. If discovery is unavailable, stop and…
  2. If the user names a product that could be in the reviewed catalogue, call search_mcp_catalog by name before handling the URL. Prefer an…
  3. Call inspect_mcp_candidate with remote_url set to the user's exact URL. Do not supply catalogue selectors at the same time.
  4. Present the returned bounded evidence. Ask the user to explicitly confirm registering this exact URL in one exact project. If inspection…
  5. After confirmation, call register_remote_mcp with the exact project, URL, optional safe display name, and a fresh idempotency key. This…
  6. If this workflow is running in a managed project assistant, present the returned dashboard setup URL when one exists, and call…
  7. For an external Platform MCP client, if next_action is secure_dashboard_setup_required, present the exact dashboard_setup_url. The user…
  8. For an external Platform MCP client, call get_mcp_readiness with the selected project and returned registration ID. For a non-ready…
  9. For an external Platform MCP client, after secure setup or authorization, call get_mcp_readiness with force: true. Do not rely on stale or…
  10. For an external Platform MCP client, when readiness is current and ready, report the server-returned evidence. Registration remains…
  11. Call get_mcp_client_admission for the same project and registration ID and report the mode it returns together with the custom client ID…

What it can do on your machine

Read from SKILL.md and the folder at commit 1378037. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Add MCP From Remote URL loads about 2k tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 1,149 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from speakeasy-api/gram at commit 1378037, republished under its AGPL-3.0 licence (© speakeasy-api). 1,149 words, ~2,043 tokens.

Download SKILL.mdSave it as .claude/skills/add-mcp-from-remote-url/SKILL.md (or your agent's skills folder).
name
add-mcp-from-remote-url
description
Add a user-supplied remote MCP server URL to an explicit AICP project through the Speakeasy AI Control Plane Platform MCP.

Add an MCP from a remote URL

Use this workflow only through the authenticated Speakeasy AI Control Plane (AICP) Platform MCP when the user supplies a remote MCP server URL that is not in the reviewed MCP Catalogue. It follows the same guarded outcome a user completes in the AICP dashboard: inspect the URL, confirm the bounded evidence and project, register privately, finish secure setup, and verify readiness. For a reviewed catalogue entry, use add-mcp-from-catalog instead. The package itself grants no organization access.

Safety rules

  • Never ask the user to paste API keys, passwords, access or refresh tokens, OAuth codes, client secrets, secret headers, or MCP credentials into chat. Authentication and headers are configured only through secure AICP dashboard setup.
  • Use inspect_mcp_candidate as the only read-only inspection step for a user-supplied URL. It returns bounded evidence and does not register or distribute anything.
  • Keep the target project explicit. Never infer it from a previous conversation or silently substitute another project.
  • Before registration, show the user the returned URL, transport, tool count and names, authentication posture, setup requirement, and OAuth-discovery state. State any missing evidence honestly.
  • Register only after the user explicitly confirms this exact remote server and project. Registration revalidates and re-inspects the URL; an earlier inspection is never trusted as admission evidence.
  • Registration is private. Do not claim the server is available to users until fresh readiness succeeds and exact-plugin distribution is rollout-enabled.
  • Show non-secret setup and authorization URLs only when a Platform MCP tool returns them.
  • Use send_platform_mcp_feedback only after asking for consent, and never include identifiers, URLs, credentials, payloads, headers, logs, or attachments.

Workflow

  1. Call list_projects to verify that the Platform MCP is authenticated and obtain eligible projects. If discovery is unavailable, stop and ask the user to complete or repair AICP OAuth.
  2. If the user names a product that could be in the reviewed catalogue, call search_mcp_catalog by name before handling the URL. Prefer an exact reviewed candidate when available.
  3. Call inspect_mcp_candidate with remote_url set to the user's exact URL. Do not supply catalogue selectors at the same time.
  4. Present the returned bounded evidence. Ask the user to explicitly confirm registering this exact URL in one exact project. If inspection reports an error or unavailable evidence, do not retry unchanged input or claim registration succeeded. Only when create_project is in your tool list, and no listed project fits or none exists yet, may you offer a new project. A managed project assistant has no create_project tool and always registers in its own project, so never offer it there. For a new project, agree its exact name and choose one idempotency key for this create; pass that same key on the preview and on the confirmed call. Call create_project with that name, that key, and confirmed: false to preview it: nothing is created, and the confirmation_required result returns the exact slug the project would get. Do not work the slug out yourself. Show that slug to the user as the project's permanent address in dashboard links; it does not change on rename. After the user confirms the name and slug, call create_project again with the same name, the same key, and confirmed: true, and use the project it returns. Use a fresh key only for a new attempt after a refusal. A conflict refusal means a project already holds that slug and nothing was created: offer that existing project or a different name. Creating a project needs organization administrator access; if it is refused, say so rather than choosing another project. Confirming the new project's name is not consent to register: once it exists, ask the user to confirm this exact URL in that exact new project before continuing.
  5. After confirmation, call register_remote_mcp with the exact project, URL, optional safe display name, and a fresh idempotency key. This re-inspects the URL and creates private project configuration only.
  6. If this workflow is running in a managed project assistant, present the returned dashboard setup URL when one exists, and call get_mcp_readiness without force to report the persisted, actor-scoped evidence. Never force a provider probe from an assistant. A freshly registered MCP normally has no persisted evidence yet and reports readiness_unavailable; that is not a reason to stop. Provider attachment does not depend on readiness evidence, but it does depend on the inspection's OAuth discovery evidence: attachment obtains a client from the provider automatically, through dynamic client registration or, when the provider supports it instead, a client ID metadata document. Only when inspection reported authentication: authentication_required with oauth_discovery: available_dcr or oauth_discovery: available_cimd (its automatic_client_registration is dynamic_client_registration or client_id_metadata_document), ask for explicit confirmation, call attach_platform_mcp_identity_provider with confirmed: true, present its exact authorization URL, and wait for the user to use Connect or Authorize there. Describe either path as automatic sign-in setup, not manual setup: the only remaining step is the user's own sign-in. When inspection reported authentication_required with oauth_discovery: available (automatic_client_registration: none), the provider advertises OAuth but neither dynamic registration nor client ID metadata documents, so do not attempt attachment; hand off to the dashboard setup URL, where the user configures a client registered with that provider or a Service Account credential. When inspection reported authentication_required with incomplete or absent OAuth discovery, the upstream expects a static credential such as an API key or Basic credential; do not attempt attachment, and tell the user to configure it as a Service Account credential through the dashboard setup URL, never in chat. When inspection reported anonymous, the endpoint needs no upstream identity provider — skip attachment and continue.
  7. For an external Platform MCP client, if next_action is secure_dashboard_setup_required, present the exact dashboard_setup_url. The user completes authentication or secret entry outside chat; never request the resulting value.
  8. For an external Platform MCP client, call get_mcp_readiness with the selected project and returned registration ID. For a non-ready result, follow only its server-provided repair action. When it requires provider attachment, ask for explicit confirmation before attach_platform_mcp_identity_provider, then present its exact authorization URL.
  9. For an external Platform MCP client, after secure setup or authorization, call get_mcp_readiness with force: true. Do not rely on stale or inferred readiness.
  10. For an external Platform MCP client, when readiness is current and ready, report the server-returned evidence. Registration remains private until a separately rollout-gated exact-plugin distribution is available.
  11. Call get_mcp_client_admission for the same project and registration ID and report the mode it returns together with the custom client ID metadata URLs it lists, which together decide which MCP clients may authorize against this server. Change it only when the user asks: explain what the proposed mode admits and refuses, ask for explicit confirmation, then call set_mcp_client_admission with that exact mode and confirmed: true. Known clients (presets) refuses an unlisted client at authorization with no fallback.
Show full SKILL.md (25 more words)Show less

OAuth consent, secret entry, and provider authorization are the expected out-of-agent stops. URL and project selection, registration confirmation, and provider-attachment confirmation stay in the conversation.

© speakeasy-api, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in server/internal/plugins/platform_mcp_skills/add-mcp-from-remote-url of speakeasy-api/gram.

Open the folder on GitHubat commit 1378037

Compare with similar skills

Add MCP From Remote URL next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Add MCP From Remote URL compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Add MCP From Remote URL this skillspeakeasy-api/gram273—~2kAutomated safety check: PassAGPL-3.0
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence
Context Mode Output Sandboxmksglu/context-mode26k—~4.1kAutomated safety check: PassCustom licence

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Context Mode Output Sandbox

    mksglu/context-mode

    Routes large command, file, API and browser output through context-mode tools so only the needed result enters the agent's context, instead of dumping it via Bash.

    26k GitHub stars~4.1k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Migrates the compatible subset of settings and global file-based MCP servers from the Warp desktop app into Warp Agent CLI without exposing credentials or state.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    Agent WorkflowsAuto-check passed

More from speakeasy-api/gram

All 39 skills in this repo
  • Gram Playwright CLI

    speakeasy-api/gram

    A skill your agent uses when automating the Speakeasy dashboard in a browser, capturing screenshots, inspecting pages.

    273 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Transactional Email

    speakeasy-api/gram

    A skill your agent uses when adding, changing, restyling, reviewing, validating, or previewing a Speakeasy transactional email, in Go or in LMX/MJML — a template<name.go, a TemplateKey constant, a…

    273 GitHub stars~4.7k tokensUpdated today
    Auto-check passed
  • Admin Shadcn

    speakeasy-api/gram

    A skill your agent uses when adding, changing, or styling UI in client/admin (the Speakeasy admin dashboard) that touches shadcn/ui — a button, dialog, table, sidebar, badge, select, tabs, tooltip…

    273 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • A skill your agent uses when adding, editing, reviewing, testing, or locating a reviewed skill distributed with the Platform MCP plugin; triggers include "Platform MCP skill", "platformmcpskills"…

    273 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Clickhouse

    speakeasy-api/gram

    A skill your agent uses when changing or reviewing Speakeasy ClickHouse schemas, migrations, queries, inserts, access principals, bootstrap SQL, Cloud compatibility, partial migration failures, or…

    273 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Feature Flag

    speakeasy-api/gram

    A skill your agent uses when gating a feature behind a flag, dogfooding or gradually rolling out a change, choosing between productfeatures and PostHog feature flags, adding or checking a product…

    273 GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Categories

Questions about Add MCP From Remote URL

What does Add MCP From Remote URL do?

Add a user-supplied remote MCP server URL to an explicit AICP project through the Speakeasy AI Control Plane Platform MCP. Add MCP From Remote URL is an agent skill from speakeasy-api/gram. Add a user-supplied remote MCP server URL to an explicit AICP project through the Speakeasy AI Control Plane Platform MCP.

When should I use Add MCP From Remote URL?

Add MCP From Remote URL fits situations like: tasks that involve MCP servers.

How do I install Add MCP From Remote URL in Claude Code?

Run `npx skills add speakeasy-api/gram --skill add-mcp-from-remote-url -a claude-code`. Or copy the skill folder (server/internal/plugins/platform_mcp_skills/add-mcp-from-remote-url in speakeasy-api/gram) into .claude/skills/add-mcp-from-remote-url in your project. Claude Code loads it when a task matches its description.

How do I install Add MCP From Remote URL in Codex?

Run `npx skills add speakeasy-api/gram --skill add-mcp-from-remote-url -a codex`. Or copy the skill folder (server/internal/plugins/platform_mcp_skills/add-mcp-from-remote-url in speakeasy-api/gram) into .agents/skills/add-mcp-from-remote-url in your project. Codex loads it when a task matches its description.

Can I use Add MCP From Remote URL in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add speakeasy-api/gram --skill add-mcp-from-remote-url -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/add-mcp-from-remote-url, .gemini/skills/add-mcp-from-remote-url, .github/skills/add-mcp-from-remote-url and .opencode/skills/add-mcp-from-remote-url in your project.

What does Add MCP From Remote URL need to run?

SKILL.md names no scripts, command-line tools or credentials: Add MCP From Remote URL is instructions for the agent only.

Does Add MCP From Remote URL access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Add MCP From Remote URL safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Add MCP From Remote URL use?

Add MCP From Remote URL is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Add MCP From Remote URL use?

About 2k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Add MCP From Remote URL?

Skills that share tags, products or a category with Add MCP From Remote URL: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars) and Crush Configuration (charmbracelet/crush, 29k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Add MCP From Remote URL?

speakeasy-api (a GitHub organization) maintains it in speakeasy-api/gram, which has 273 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on October 9, 2026.

Source: speakeasy-api/gram on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.