Skip to content
Back to skills

Mcps

ASecurity

List the partner's external MCP servers, ACTIVE (configured) and PENDING (staged, awaiting your approval). Diagnostic, no writes, no secrets.

  • 10 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 3, 2026
ai-agents

Works with

  • cli
  • mcp

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add xgre1/troth --skill mcps --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Mcps?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Mcps
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/xgre1-mcps/badge)](https://www.skillsdirectory.com/skills/xgre1-mcps)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: mcps
description: List the partner's external MCP servers, ACTIVE (configured) and PENDING (staged, awaiting your approval). Diagnostic, no writes, no secrets.
allowed-tools: [mcp_list]
kind: deterministic
---

User wants to see the partner's external MCP "hands": which servers are ACTIVE
(usable now) and which are PENDING (staged via mcp_register_request and waiting
for operator approval).

Read-only protocol (never spawns a server, never prints a secret):

1. ACTIVE servers come from the resolved registry: the global
   `~/.troth/mcp-clients.json` merged with the current project's `.mcp.json`
   (project wins collisions). List each by name and transport (`http` or
   `stdio`) ONLY. Do NOT print env values, `$vault` refs, or remote urls, and
   do NOT spawn a server to count its tools (that would need a real process).
2. PENDING servers come from `~/.troth/mcp-pending.json`. List each by name +
   its one-line note, marked "awaiting your approval". Never print its config.

Reply structure (terse):

```
MCP servers (the partner's external hands):

ACTIVE (N):
  - <name>  [http|stdio]

PENDING (N):
  - <name>  (awaiting your approval) - <note>
```

Approval stays operator-tap: staging a server never activates it. The operator
approves from the app popup, or with `troth mcp approve <name>`; reject with
`troth mcp reject <name>`. Do NOT write anything to substrate during this
command; it is diagnostic by design.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…