Agent Skills vs MCP vs Plugins: What Each Is and When to Use It
An agent skill is a SKILL.md folder an agent loads on demand; MCP is a live protocol to tools and data; a plugin bundles both. What to use when.
Tool poisoning, prompt injection through tool output, and config-level attacks on the Model Context Protocol — how they work and how to scan for them.
The Model Context Protocol gives an agent a typed list of tools it can call, each described in natural language. That description is part of the model's prompt, which makes an MCP server a write channel into the agent's instructions — a hostile or compromised server can poison a tool description, smuggle directives through tool output, or hide metadata a human reviewing the config never sees.
These posts cover the documented attack classes, the standards work responding to them, and the practical checks. SkillSafe's MCP scanner reads a config and flags poisoning and exfiltration patterns before the agent ever connects.
14 articles in this guide
An agent skill is a SKILL.md folder an agent loads on demand; MCP is a live protocol to tools and data; a plugin bundles both. What to use when.
MCP is not safe by default. Twelve checks, by phase, for vetting an MCP server before install and constraining it at the call, in flight and on update.
Arcade.dev raised $60M in June 2026 for an agent authorization layer. What scoped permissions, MCP tool policy and audit trails mean for your agent stack.
Agentjacking hijacks AI coding agents with a fake Sentry error. Tenet found 2,388 exposed orgs, 100+ agents running attacker code, an 85% success rate.
An IETF Internet-Draft names 6 recurring MCP vulnerability classes and states that the MCP specification defines no normative security requirements.
An AI agent provisioned five AWS instances to port-scan DN42 and ran up $6,531.30 in about 24 hours. Cost, scope and rate are tool permissions, not prompt text.
An Agent Bill of Materials lists every skill, plugin, MCP server, credential and paired device an agent can reach. OpenClaw's ClawJacked bug is why you need one.
Cisco Cloud Control puts AI agents, MCP connectors and a 50-partner tool marketplace inside infrastructure operations. What admission control that now requires.
VIPER-MCP scanned 39,884 MCP server repos and confirmed 106 zero-days, 67 with CVE IDs. Agent tools need code-level taint analysis, not trust prompts.
Microsoft's Agent Control Specification evaluates agent policy at 8 intervention points and returns 1 of 5 verdicts: allow, warn, deny, escalate, transform.
The NSA's May 2026 MCP guidance treats agent tooling as infrastructure: inventory every server, verify tool changes, and scan before trust drifts.
OX Security found a remote code execution design flaw in MCP's official SDKs: 10 CVEs, 30+ disclosures, 7,000+ exposed servers. Treat MCP servers as code.
MCP tool poisoning hides attacker instructions in tool description metadata your model reads and your UI never shows. How it works, and how to detect it.
Claude Code skills run with your files, shell and credentials. ClawHavoc put 1,184 malicious skills in one registry. How to check one before you install.