Crafting AI Prompts Framework

MCP and Skills

Last updated: Sep 30, 2026

When building advanced coding agents, you have two primary ways to extend their capabilities: Model Context Protocol (MCP) and Skills. While they often seem interchangeable, they serve fundamentally different purposes in your agent's architecture. This page explains the technical differences, the hidden costs of using MCPs incorrectly, and how to orchestrate them together for a high-performance workflow.


Model Context Protocol (MCP)

MCP is an open standard that acts as a universal adapter, enabling AI models to connect securely to external data and tools. When you connect an MCP Server (e.g., GitHub, PostgreSQL, Google Drive), you are exposing a set of deterministic API endpoints to the Agent.

Think of MCP as the agent's Hands. It executes specific, code-based actions.

  • Deterministic: Inputs and outputs are handled via strict code/APIs.
  • External Execution: The logic runs on a server, not inside the LLM.
  • Schema-Based: The Agent learns how to use the tool by reading a strictly defined JSON schema.

A2A - Agent to Agent

There is also the Agent to Agent (A2A) protocol. While MCP connects an agent to tools (Vertical Integration), A2A connects an agent to other agents (Horizontal Integration).

Think of A2A as the agent's Team. It enables a primary "Orchestrator" agent to delegate sub-tasks to specialized agents (e.g., a generic coder delegating to a database specialist).

  • Discovery: Agents find each other using "Agent Cards" (JSON manifests) that broadcast their specific capabilities.
  • Interoperability: It uses a standardized schema (often JSON-RPC) allowing agents from different frameworks to collaborate securely.
  • Delegation: Instead of doing everything itself, an agent can hand off a complex task to a peer and await the result, preserving its own context window.

Skills

Skills are domain-specific instructions, typically stored as local Markdown files. Unlike MCPs, which represent tools, Skills represent behavior.

Think of Skills as the agent's Brain or training manual. They guide the agent on how to approach a problem before it tries to solve it.

  • Behavioral: Defines workflows (e.g., "Always check for existing bugs before creating a new issue").
  • Local: Stored in your project directory (e.g., .claude/skills/python-style-guide.md).
  • Flexible: Relies on the LLM's reasoning capabilities rather than rigid API schemas.

The following resources are also worth taking into account when working with skills. 

The Context Trap

A common pitfall when building agents is the misuse of MCP servers, leading to rapid context window exhaustion. This is often referred to as "The Context Trap."

The Schema Dump

When you connect an MCP server, it must "announce" itself to the LLM. It does this by injecting a Tool Definition Schema into the System Prompt. This schema describes every available function, parameter, and required input type.

For a robust tool like the GitHub MCP, this definition is massive. It includes schemas for searching issues, reading PRs, listing commits, file operations, and branch management.

The Impact:

By simply connecting the GitHub MCP, you might consume 30% or more of your context window before you have even typed your first instruction. This leaves significantly less room for your actual code, conversation history, and reasoning.


Orchestrating with Skills

The solution is not to choose between them, but to use Skills to manage MCP usage. Instead of giving the agent raw, unguided access to heavy tools, you use a lightweight Skill as a "Gatekeeper."

The Strategy: Load a small textual Skill (a few KB) that instructs the agent when to use the specific MCP tool. This keeps the initial context usage low and prevents the agent from "tool spamming" (retrieving too much data via the API).

FeatureMCP (Model Context Protocol)Skills
Primary RoleThe Hands: Executes actions (APIs, DB queries).The Brain: Guides behavior and strategy.
Context CostHigh (Loads tool schemas)Low (Just markdown text)
ExecutionDeterministic API calls.LLM interpretation.
Best ForFetching data, executing code, precise operations.Defining workflows, gating tools, best practices.

By combining these two powerful concepts, you ensure your agent remains context-efficient while retaining the ability to perform complex, external actions.


Community Libraries

To help you get started faster, we have established dedicated libraries for both MCP Servers and Skills directly on this website. Whether you are looking for a standard GitHub integration or a specialized debugging workflow, you can find validated resources here.


Security Warning: Skill Poisoning

As the ecosystem grows, developers are sharing Skills rapidly. While this collaboration is powerful, downloading unverified Skills introduces a new security vector known as Skill Poisoning.

Because Skills are essentially natural language instructions, bad actors can embed "jailbreak" commands or malicious logic deep within a Markdown file. If not carefully reviewed, a poisoned Skill could trick your agent into exfiltrating sensitive data or introducing vulnerabilities into your codebase without you noticing.

Risk Alert: We manually validate "Official" skills on our library, but you should always inspect the .md content of any community Skill before adding it to your agent.

To understand how Skill Poisoning works and how to protect your agentic workflow, read our full security breakdown below.

TL;DR - About this page

The three phases

CRAFT

Craft (write) the prompt with the following elements: Context, Register, Acting Role, Format, and Task.

ING

Validate the prompt and ensure it maintains an interactive approach. Keep in mind the importance of non-disclosure and staying goal-driven throughout the process.

AI

Continuously assess and refine the output based on the prompts output to improve the overall quality.

Terms of Service

Before accessing the "Prompt Injections" examples on our website, please read and agree to the following terms of service:

  1. Educational Purpose Only: The "Prompt Injections" examples provided are intended solely for educational purposes. They are meant to help you understand how prompt injections work and how to defend yourself against them.
  2. No Misuse: You agree not to use the provided examples for any malicious or unethical activities. This includes, but is not limited to, using prompt injections to manipulate, deceive, or harm others.
  3. Responsible Use: By accessing these examples, you confirm that your intention is to learn about the risks associated with prompt injections and to enhance your ability to safeguard against them.
  4. Legal Compliance: You agree to comply with all applicable laws and regulations while using the information provided on this website.
  5. No Liability: We are not responsible for any misuse of the information provided on our website. Users are solely responsible for their actions and any consequences that may arise from the use of this information.

By clicking "I agree," you accept these terms for this documentation visit. "I agree & save" remembers your choice for future visits in this browser. If you decline, the examples remain hidden.