MCP Adapter Design
Design thin MCP adapters with bounded schemas, trusted application identity, shared authorization, and explicit effects rather than treating instructions as permissions.
7 CANONICAL SKILLS · V0.2.0
Canonical public skills plus private context bindings, thin authenticated adapters, and bounded execution contracts.
Run from a full toolkit checkout. This prints a file manifest, not an installer.
node tools/bundle.mjs resolve mcp-toolingDesign thin MCP adapters with bounded schemas, trusted application identity, shared authorization, and explicit effects rather than treating instructions as permissions.
Select canonical public skills and bind private repository context separately without copying instructions, silently installing packages, or broadening tool authority.
Assemble task-sized context from current canonical source, accepted contracts, graphs, and semantic tools while tracking freshness and missing information.
Enforce tenant-scoped operations across transports, jobs, data, and caches using trusted identity and independent cross-tenant denial tests.
Compare actual compiler, runtime, package-manager, container, and agent-tool identities across environments and verify targeted drift corrections.
Turn an engineering request into a bounded work packet with owned paths, dependencies, acceptance criteria, verification commands, and a handoff contract. Use before delegating non-trivial repository work.
Qualify a specific third-party MCP server revision through identity, effect review and actual protocol/operation evidence rather than treating discovery as approval.
Pick the skill needed for the current task. A private adapter supplies project-specific roots, command IDs, accepted contracts, and policy. It should pin and verify the public revision before exposing guidance to an internal agent.
Skill effectiveness remains experimental. Package validation and content hashes do not establish host compatibility, artifact authenticity, or permission to execute.
Read the private-adapter boundary ↗