Skip to content

Skills, MCP servers or plugins: which one, and where each lives

A coding agent has seven extension points: AGENTS.md (standing rules), skills (procedures loaded on demand), slash commands (procedures a person triggers), subagents (isolated side tasks), hooks (checks that always run), MCP servers (live external systems) and plugins (bundles of the rest). Choose by job, then measure context cost.

A colleague asks the agent to open a PR “the way we do it here”. The agent has three sources of instructions, two GitHub integrations and a forgotten hook, and it follows the wrong one. This page helps developers and tech leads decide where a rule or tool belongs.

MechanismEnters contextReach for it whenNot forCanonical page
AGENTS.md (CLAUDE.md, Cursor Rules)Every session, in fullbuild and test commands, rules for every tasklong procedures, API docsRepository context files
Skill (SKILL.md folder)Name and description always, body when it firesa repeatable procedure: TDD, a release checklistcredentials, live dataAgent skills
Slash command (in Claude Code, a skill with disable-model-invocation: true)Only when a person types itsteps that must never start alone: a deploy, a release cutanything the agent should pick up unpromptedCustom commands and skills
SubagentIts own window; only a summary returnsnoisy searches, a second-opinion reviewwork that needs the main thread’s contextCustom subagents
HookNothing, unless it returns outputrules that must hold every time: format on edit, block a secretadvice the model may weighHooks
MCP serverTool schemas plus every resultreading or changing external state: PRs, tickets, a browserconventions and styleMCP servers
Plugin (a versioned bundle of the above)Whatever it bundlesa vendor’s skills and server together, or a team’s standard setupa rule one line in AGENTS.md coversPlugins

The test: a skill tells the agent how, an MCP server lets it act, and a hook makes sure it did. A rule the agent may ignore belongs in AGENTS.md or a skill; a rule it must never break belongs in a hook or in CI.

  • Plugins became the default install route. On 2026-09-26, claude-plugins-official listed 314 plugins, openai-curated 65 and cursor/plugins 94.
  • Context cost became the selection criterion. claude plugin details (Claude Code 2.1.283, 2026-09-26): about 838 tokens per session for superpowers, 41,515 for Everything Claude Code.
  • Churn is high. GSD is now @opengsd/gsd-core; openai/skills gave way to openai/plugins.
  1. Record the baseline: /context in Claude Code. Codex and Cursor have no verified equivalent, so count servers with codex mcp list and skills with npx skills list. claude plugin details <name> prints any plugin’s projected token cost, even for skills you install elsewhere.

  2. Install one discipline pack. Matt Pocock’s skills cover grilling, specs, tickets, TDD and review.

    Terminal window
    claude plugin install mattpocock-skills@claude-plugins-official --scope project
    claude plugin details mattpocock-skills

    grill-me is a one-line delegate that fails without grilling. Write --skill grill-me, never --skill=grill-me, which skills 1.7.0 drops silently. Plugin skills are namespaced: /mattpocock-skills:grill-me in Claude Code; an npx skills copy is /grill-me in Cursor and $grill-me in Codex.

  3. Add GitHub and Context7. Read a fine-grained, single-repository token from a secret store (macOS Keychain here), never paste it. The GitHub MCP page lists minimum scopes and the /readonly URL.

    Terminal window
    export GITHUB_PERSONAL_ACCESS_TOKEN="$(security find-generic-password -s gh-mcp -w)"
    claude plugin install github@claude-plugins-official --scope project
    claude mcp add --transport http --scope project context7 https://mcp.context7.com/mcp
  4. Measure again in a new session. If the cost outweighs the value, remove something.

  5. Commit .claude/settings.json, .mcp.json and .cursor/mcp.json so the team gets the same setup through review. codex mcp add writes to your user config, so each Codex user repeats step 3. Each teammate still exports their own GITHUB_PERSONAL_ACCESS_TOKEN (the plugin reads exactly that name); tokens never go into the committed files.

How you know the setup works without reading every line

Section titled “How you know the setup works without reading every line”
  • Context budget: the step 1 and step 4 numbers, recorded in the PR; see reducing MCP token cost.
  • Deterministic gates: tests, type checks and a Gitleaks pre-commit hook.
  • A second model: codex review or a review bot; see agent PR review.
  • Sign-off: the tech lead reviews MCP and plugin changes as dependencies.
SymptomCauseRecovery
Every skill appears twiceInstalled as a plugin and with npx skillsKeep one route
The agent ignores a “must” ruleThe rule lives only in proseMove it into a hook or a CI check
An MCP result asks the agent to do something oddPrompt injection through fetched contentUse read-only scopes; see MCP security

Where to go next from the ecosystem overview

Section titled “Where to go next from the ecosystem overview”
Edit page

Last updated:

Cite this page — https://developertoolkit.ai/en/ecosystem/, developertoolkit.ai