Conversation
Packages agent-plugin/skills/ into the jar and exposes each file as a skill://<name>/<path> MCP resource (SEP-2640's resource-mapping half), so a client that connects to chromatik-mcp gets the driving-chromatik house rules without installing the agent plugin, and the served text is version-locked to the jar rather than a separately-installed copy. The server's INSTRUCTIONS now point the model at skill://driving-chromatik/SKILL.md. SEP-2640's skills/list and skills/get methods (and the extensions capability) are deliberately deferred: the MCP Java SDK 2.0.0-RC1's ServerCapabilities is a fixed record and its request handlers are private, with no seam for either — they wait on modelcontextprotocol/java-sdk#1141. A client can still read every skill file directly via resources/read in the meantime, which is the baseline SEP-2640 guarantees. Co-Authored-By: Claude Opus 5.5 <[email protected]>
Packages agent-plugin/skills/ into the jar and exposes each file as a skill://<name>/<path> MCP resource (SEP-2640's resource-mapping half), so a client that connects to chromatik-mcp gets the driving-chromatik house rules without installing the agent plugin, and the served text is version-locked to the jar rather than a separately-installed copy. The server's INSTRUCTIONS now point the model at skill://driving-chromatik/SKILL.md. SEP-2640's skills/list and skills/get methods (and the extensions capability) are deliberately deferred: the MCP Java SDK 2.0.0-RC1's ServerCapabilities is a fixed record and its request handlers are private, with no seam for either — they wait on modelcontextprotocol/java-sdk#1141. A client can still read every skill file directly via resources/read in the meantime, which is the baseline SEP-2640 guarantees. Co-authored-by: Claude Opus 5.5 <[email protected]>
|
There is a fail-open deserialization behavior here that conflicts with SEP-2640's integrity model. The new test SEP-2640 is stricter: This seems security-relevant because the extension's approval/integrity model depends on exact resource metadata. I would make wire deserialization fail closed for required fields (while keeping constructor ergonomics separately if desired), and flip these tests to assert rejection of missing required members. AI-assisted review; I checked current head against SEP-2640 before posting. |
Closes #1140
Motivation and Context
Adds support for the SEP-2640 Skills extension.
This enables Java MCP clients to discover and retrieve Agent Skills, and stateless Java MCP servers to advertise and serve them. The implementation adds the extension schema and endpoints (
skills/list,skills/get, and optionalresources/directory/read), client APIs, server registration APIs, manifest validation, documentation, and tests.This aligns the Java SDK with existing implementations in:
How Has This Been Tested?
./mvnw clean test.Breaking Changes
No. This change adds new APIs and protocol types without changing existing behavior.
Types of changes
Checklist
Additional context
I prepared this implementation before realizing that the project prefers discussion with maintainers before non-trivial changes are submitted. I would appreciate feedback on the scope and API design, and I am happy to revise the implementation based on maintainer guidance.