Skills, MCP servers or plugins: which one, and where each lives
A coding agent has seven extension points: AGENTS.md (standing rules), skills (procedures loaded on demand), slash commands (procedures a person triggers), subagents (isolated side tasks), hooks (checks that always run), MCP servers (live external systems) and plugins (bundles of the rest). Choose by job, then measure context cost.
A colleague asks the agent to open a PR “the way we do it here”. The agent has three sources of instructions, two GitHub integrations and a forgotten hook, and it follows the wrong one. This page helps developers and tech leads decide where a rule or tool belongs.
Which mechanism does this job?
Section titled “Which mechanism does this job?”| Mechanism | Enters context | Reach for it when | Not for | Canonical page |
|---|---|---|---|---|
AGENTS.md (CLAUDE.md, Cursor Rules) | Every session, in full | build and test commands, rules for every task | long procedures, API docs | Repository context files |
Skill (SKILL.md folder) | Name and description always, body when it fires | a repeatable procedure: TDD, a release checklist | credentials, live data | Agent skills |
Slash command (in Claude Code, a skill with disable-model-invocation: true) | Only when a person types it | steps that must never start alone: a deploy, a release cut | anything the agent should pick up unprompted | Custom commands and skills |
| Subagent | Its own window; only a summary returns | noisy searches, a second-opinion review | work that needs the main thread’s context | Custom subagents |
| Hook | Nothing, unless it returns output | rules that must hold every time: format on edit, block a secret | advice the model may weigh | Hooks |
| MCP server | Tool schemas plus every result | reading or changing external state: PRs, tickets, a browser | conventions and style | MCP servers |
| Plugin (a versioned bundle of the above) | Whatever it bundles | a vendor’s skills and server together, or a team’s standard setup | a rule one line in AGENTS.md covers | Plugins |
The test: a skill tells the agent how, an MCP server lets it act, and a hook makes sure it did. A rule the agent may ignore belongs in AGENTS.md or a skill; a rule it must never break belongs in a hook or in CI.
Where each layer lives in the ecosystem
Section titled “Where each layer lives in the ecosystem”What changed in 2026
Section titled “What changed in 2026”- Plugins became the default install route. On 2026-09-26,
claude-plugins-officiallisted 314 plugins,openai-curated65 andcursor/plugins94. - Context cost became the selection criterion.
claude plugin details(Claude Code 2.1.283, 2026-09-26): about 838 tokens per session forsuperpowers, 41,515 for Everything Claude Code. - Churn is high. GSD is now
@opengsd/gsd-core;openai/skillsgave way toopenai/plugins.
Equip one repo from zero
Section titled “Equip one repo from zero”-
Record the baseline:
/contextin Claude Code. Codex and Cursor have no verified equivalent, so count servers withcodex mcp listand skills withnpx skills list.claude plugin details <name>prints any plugin’s projected token cost, even for skills you install elsewhere. -
Install one discipline pack. Matt Pocock’s skills cover grilling, specs, tickets, TDD and review.
Terminal window claude plugin install mattpocock-skills@claude-plugins-official --scope projectclaude plugin details mattpocock-skillsTerminal window npx skills add mattpocock/skills --skill grill-me grilling setup-matt-pocock-skills -a codexTerminal window npx skills add mattpocock/skills --skill grill-me grilling setup-matt-pocock-skills -a cursorgrill-meis a one-line delegate that fails withoutgrilling. Write--skill grill-me, never--skill=grill-me, whichskills1.7.0 drops silently. Plugin skills are namespaced:/mattpocock-skills:grill-mein Claude Code; annpx skillscopy is/grill-mein Cursor and$grill-mein Codex. -
Add GitHub and Context7. Read a fine-grained, single-repository token from a secret store (macOS Keychain here), never paste it. The GitHub MCP page lists minimum scopes and the
/readonlyURL.Terminal window export GITHUB_PERSONAL_ACCESS_TOKEN="$(security find-generic-password -s gh-mcp -w)"claude plugin install github@claude-plugins-official --scope projectclaude mcp add --transport http --scope project context7 https://mcp.context7.com/mcpTerminal window export GITHUB_PAT_TOKEN="$(security find-generic-password -s gh-mcp -w)"codex mcp add github --url https://api.githubcopilot.com/mcp/ --bearer-token-env-var GITHUB_PAT_TOKENcodex mcp add context7 --url https://mcp.context7.com/mcpAdd Context7 to
.cursor/mcp.json:{ "mcpServers": { "context7": { "url": "https://mcp.context7.com/mcp" } } }For GitHub in Cursor, follow the token setup on the GitHub MCP page.
-
Measure again in a new session. If the cost outweighs the value, remove something.
-
Commit
.claude/settings.json,.mcp.jsonand.cursor/mcp.jsonso the team gets the same setup through review.codex mcp addwrites to your user config, so each Codex user repeats step 3. Each teammate still exports their ownGITHUB_PERSONAL_ACCESS_TOKEN(the plugin reads exactly that name); tokens never go into the committed files.
How you know the setup works without reading every line
Section titled “How you know the setup works without reading every line”- Context budget: the step 1 and step 4 numbers, recorded in the PR; see reducing MCP token cost.
- Deterministic gates: tests, type checks and a Gitleaks pre-commit hook.
- A second model:
codex reviewor a review bot; see agent PR review. - Sign-off: the tech lead reviews MCP and plugin changes as dependencies.
When a layered setup goes wrong
Section titled “When a layered setup goes wrong”| Symptom | Cause | Recovery |
|---|---|---|
| Every skill appears twice | Installed as a plugin and with npx skills | Keep one route |
| The agent ignores a “must” rule | The rule lives only in prose | Move it into a hook or a CI check |
| An MCP result asks the agent to do something odd | Prompt injection through fetched content | Use read-only scopes; see MCP security |
Where to go next from the ecosystem overview
Section titled “Where to go next from the ecosystem overview”- Before this: Git worktrees for parallel agents, the previous step in the developer track.
- Plugins and marketplaces to pin versions per agent.
- Agentic development frameworks compared to choose one discipline pack; discipline packs walks one feature from grilling to verification.
- Model routing by evidence, the next step in the developer track.