Exploring MCP Servers with GitHub Copilot

Pamela Fox

pamelafox.github.io/github-copilot-mcp-skills-workshop

Model Context Protocol logo in blue, cyan, and lavender GitHub Copilot mascot GitHub Copilot mascot facing the title

About me

Pamela Fox

Principal Cloud Advocate at Microsoft / GitHub

Formerly: UC Berkeley, Coursera, Khan Academy, Google

Pamela Fox smiling beside an Olaf statue

About you

Turn to your neighbor and introduce yourself:

  • Name
  • Location
  • What sessions have you liked so far at the conference?
  • What's your favorite coding agent or model?
  • Make up a new meaning for "MCP" (e.g. "More Coffee Please")

Today's agenda

TimeFormatActivity
11:00โ€“11:15WelcomeIntroductions, GitHub Copilot, and Codespaces
11:15โ€“11:25ExerciseSet up environment and GitHub Copilot
11:25โ€“11:45PresentationMCP: Model Context Protocol
11:45โ€“12:00ExerciseConnect GitHub Copilot to an MCP server
12:00โ€“12:10PresentationAuthenticated MCP servers
12:10โ€“12:30ExerciseConnect GitHub Copilot to GitHub MCP server
12:30โ€“12:40PresentationAgent skills
12:40โ€“12:55ExerciseRun agent skills in GitHub Copilot
12:55โ€“1:00PresentationNext steps

GitHub Copilot, wherever you work

VS Code

Chat and agent mode in your editor, right next to your code.

Copilot CLI

An agent in your terminal that reads files and runs commands.

Copilot app

A standalone app for working with Copilot outside the editor.

Cloud agents

Assign a task on GitHub, and Copilot works in the cloud and opens a pull request.

Today, you'll use either VS Code, Copilot CLI, or the Copilot app.
Try Cloud Agents on your own later.

GitHub Codespaces

  • A cloud development environment with VS Code in your browser
  • Built from the repository's dev container: Python, uv, dependencies, and extensions are ready to go
  • Nothing to install on your laptop
  • Personal accounts include a free monthly quota
  • Use VS Code or Copilot CLI inside it; the Copilot app can't be used in a codespace
GitHub Code menu with the Codespaces tab and a Create codespace on main button
10 min

Exercise 1:Set up environment and GitHub Copilot

GitHub repository: ๐Ÿ”— github.com/pamelafox/github-copilot-mcp-skills-workshop

Open full exercise: ๐Ÿ”— exercise1.md

Exercise steps:

  1. Fork the workshop repository into your account.
  2. Choose Codespaces, a Dev Container, or a local environment.
  3. Install dependencies and verify Python.
  4. Open Copilot in VS Code, CLI, or the Copilot app.
  5. Confirm that Copilot recognizes the workshop repository.

MCP: Model Context Protocol

AI agents

Agent loop
User query LLM Goal Tools

An AI agent uses an LLM to run tools in a loop to achieve a goal.

Agents are often augmented by:

  • Context from files, docs, or databases
  • Memory across a session or project
  • Human approvals and feedback

๐Ÿ”— Simon Willison on defining agents

AI agents are used on a daily basis

Coding agents

GitHub Copilot ยท Claude Code ยท Codex ยท Pi

Chatbots

ChatGPT ยท M365 Copilot ยท Gemini

Assistants

OpenClaw ยท Hermes ยท Meta Muse ยท Grok Bot

Chat assistant running three web search tool calls before answering a question about a 1990s email program

Build your own agents

You can build your own agents in any language, with frameworks like:

LangChain

  • Python
  • JavaScript

Microsoft Agent Framework

  • Python
  • .NET
  • Go

Pydantic AI

  • Python

The agentic loop in action

Agent loop
User query LLM Goal Tools
User
Can I reorder my last bakery order for pickup today?
LLM
find_customer("Pamela")
Tool result
customer_id = "cust_42"
LLM
get_last_order("cust_42")
Tool result
items = [croissant, baguette]
LLM
check_inventory(items)
Tool result
croissant yes; baguette sold out
LLM
find_substitute("baguette")
Tool result
substitute = sourdough
Answer
I can reorder it with sourdough instead. Want me to place it?

Agents rely on LLM tool-calling

LLMs have been trained to know how to "call tools".

  • LLM sees the available tools and their descriptions.
  • LLM suggests a tool name and arguments.
  • Agent runtime runs the actual code.
  • Tool result is sent back to the LLM as context.
  • LLM decides whether to call another tool or answer.

The model does not execute the tool.
The runtime does.

User request LLM suggested tool call get_last_order("cust_42") Agent runtime executes tool tool result items = [...]

MCP: Model Context Protocol

MCP is the open standard that tells agent runtimes how to discover and connect to the tools they can call.

๐Ÿค– AI agent ๐Ÿ—„๏ธ Database ๐Ÿ“ง Emails GitHub MCP MCP MCP

๐Ÿ”— MCP specification: modelcontextprotocol.io

MCP architecture

MCP Host Example: GitHub Copilot MCP Client A MCP Client B MCP Server A MCP Server B Tools Prompts Resources Tools Prompts Resources MCP MCP

MCP client/server request flow

MCP Client MCP Server โ‘  Discover tools {"method": "tools/list"} {"tools": [{"name": "get_product", "description": "...", "inputSchema": {...}}, ...]} โ‘ก Call a tool {"method": "tools/call", "params": {"name": "get_product", "arguments": {"id": 1}}} {"content": [{"type": "text", "text": "Product: Widget (id=1), $9.99"}]}

MCP clients

Support for MCP features varies across MCP hosts:

caniuse.dev comparison of MCP feature support in Claude Code, Codex, Copilot, and VS Code

๐Ÿ”— caniuse.dev/host-compare

Configure VS Code with public MCP server

Add to .mcp.json

{
 "mcpServers": {
  "microsoft-learn": {
   "type": "http",
   "url": "https://learn.microsoft.com/api/mcp"
  }
 }
}

Or install from Extensions

Search @mcp in the Extensions view:

VS Code Extensions view searching @mcp, showing the GitHub MCP server with an Install button

Configure Copilot CLI with public MCP server

Add remote servers to your Copilot CLI user configuration.

1. Add the server

copilot mcp add --transport http microsoft-learn https://learn.microsoft.com/api/mcp

2. Verify the server

Start Copilot CLI:

copilot

Then run:

/mcp show microsoft-learn

Configure Copilot app with public MCP server

1
Open Customize โ†’ MCP โ†’ Add server โ†’ Add custom server.
2
Give the server a name.
3
Select HTTP as the server type.
4
Enter the server URL:
https://learn.microsoft.com/api/mcp
5
Select Add server.
6
Confirm the server shows as enabled and loaded with a green check mark.
Copilot app Add MCP Server dialog configured for the Microsoft Learn HTTP server

Adding an MCP server is a trust decision

An MCP server gives the agent new abilities, and it acts with your access.

๐Ÿ–ฅ๏ธ Who runs it?

Local servers run code on your machine. Remote servers see every request you send.

๐Ÿ”ง What can it do?

Some tools only read. Others change files, repositories, or shared services.

๐Ÿ“ฅ What comes back?

Tool descriptions and results are untrusted input that can steer the agent.

You exercise your control at two moments:
when you connect a server, and each time a tool is called.

Approving a tool call

VS Code tool approval dialog for Create Pull Request, showing the title and description arguments, a warning that it changes remote state, and Allow in this Session and Skip buttons 1 2 3 4
1
Which tool? A write tool deserves more scrutiny than a search.
2
What arguments? Read exactly what will be sent.
3
What changes? Remote state means other people will see it.
4
For how long? Session approval skips future prompts. Skip anything surprising.
15 min

Exercise 2:Connect GitHub Copilot to an MCP server

GitHub repository: ๐Ÿ”— github.com/pamelafox/github-copilot-mcp-skills-workshop

Open full exercise: ๐Ÿ”— exercise2.md

Exercise steps:

  1. Connect the Microsoft Learn MCP server.
  2. Inspect tool schemas before using them.
  3. Run one grounded documentation query.

Authenticated MCP servers

How MCP servers restrict access

The server decides how you prove access. You'll see one of these:

Private network Client MCP server

Private network

The server is only reachable from inside a company network or VPN.

You: connect from the right network. No sign-in prompt.

Client key header MCP server

Key-based access

You paste an API key or token, and the client sends it in a header.

Watch out: keys can leak. Never commit them to .mcp.json.

Client Auth server MCP server login token bearer token

OAuth-based access

You sign in through the browser, and the client stores a token for you.

Example: GitHub MCP, which also accepts a personal access token.

What happens when you sign in

User MCP Client Authorization Server MCP Server Starts the server or calls a tool Redirects to AS with authorization request Presents authentication prompt Enters credentials Authenticates user and validates client registration Displays consent page for client Grants consent Issues authorization code Exchanges code for access token Returns access token MCP request + access token Authenticated result or error

Every request carries your token

After sign-in, the client sends your token with each tool call:

MCP Client MCP Server Verifies the access token and returns results scoped to that signed-in user. MCP Authorization: Bearer <access_token> { "jsonrpc": "2.0", "method": "tools/call", "params": { "name": "list_issues", "arguments": { "repo": "..." } } } MCP { "jsonrpc": "2.0", "result": { "content": [ { "title": "Fix quiz bug" }, ... ] } }

Authentication vs. authorization

Authentication

Proves who you are, usually with OAuth in the browser. Some clients also accept a personal access token.

GitHub example: your GitHub account, plus any org SSO policy.

Authorization

Decides what each call may read or change, based on your account's permissions.

GitHub example: the repositories and orgs you can access.

The agent can do anything your account can do, within the access you granted.

GitHub MCP server

GitHub's official MCP server connects agents to the GitHub platform.

  • Remote: hosted by GitHub at https://api.githubcopilot.com/mcp/
  • Local: run it with Docker or a binary
  • Sign in: OAuth or a personal access token

GitHub groups its tools into toolsets, for example:

Repositories

repos

Browse code, search files, read commits

Issues & PRs

issues pull_requests

Create, triage, review, and update

Actions

actions

Check workflow runs and build failures

Security

code_security dependabot

Review code scanning and Dependabot alerts

Authenticated servers can expose write tools

Read and write tools carry different kinds of risk.

๐Ÿ‘€ Read

  • Can expose private source or metadata
  • Can ingest untrusted issue text
  • Still deserves review
  • Example: get_file_contents

โœ๏ธ Write

  • Changes shared state
  • Can notify or affect other people
  • Verify target and payload
  • Example: create_pull_request
Authenticated does not mean approved.
Remember: You can configure agents to require approvals for all write tools.
20 min

Exercise 3:Connect GitHub Copilot to GitHub MCP

GitHub repository: ๐Ÿ”— github.com/pamelafox/github-copilot-mcp-skills-workshop

Open full exercise: ๐Ÿ”— exercise3.md

Exercise steps:

  1. Connect GitHub MCP with authenticated tools.
  2. List and choose an open quiz issue.
  3. Run and repair the quiz locally.
  4. Commit the focused change to your fork.
  5. Open a pull request to the workshop repository.

Agent skills

What is an agent skill?

A folder with SKILL.md instructions, plus optional scripts, references, and assets.

Folder layout

pdf-processing/
โ”œโ”€โ”€ SKILL.md
โ”œโ”€โ”€ scripts/
โ”‚   โ””โ”€โ”€ extract.py
โ”œโ”€โ”€ references/
โ”‚   โ””โ”€โ”€ REFERENCE.md
โ””โ”€โ”€ assets/

SKILL.md

---
name: pdf-processing
description: Extract PDF text, fill forms,
  merge files. Use when handling PDFs.
---

# PDF processing

1. Run scripts/extract.py on the file.
2. See references/REFERENCE.md for
   form field details.

๐Ÿ”— agentskills.io

How coding agents run skills

1. Discover

Only each skill's name and description are in context.

2. Activate

When a task matches a description, the agent reads the full SKILL.md.

3. Execute

Scripts, references, and assets are loaded only as needed.

Well designed skills are activated only when needed -
not over-activated or under-activated.

Where skills live

Project level

.agents/skills/pr-summary-report/SKILL.md

Committed with the repository and shared with everyone who works on it.

Copilot also reads .github/skills/

User level

~/.agents/skills/my-skill/SKILL.md

Available across all of your projects.

Copilot also reads ~/.copilot/skills/

Third-party skills

Option 1: GitHub CLI

gh skill install mattpocock/skills

Option 2: skills CLI

npx skills add mattpocock/skills

Both let you choose where to install: project or user level, and for which agents.

Third-party skills run with agent permissions. Review their instructions and scripts before invoking them.

Discovering skills

Browse directories

Search from your command line

  • gh skill search <topic>
    Search GitHub for skills
  • gh skill preview <repo> <skill>
    Read a skill before installing it
Awesome GitHub Copilot skills directory, with skill cards and Copy install buttons

Skills over MCP

An official MCP extension lets servers ship skills alongside their tools.

How it works

  • Server declares the skills extension
  • skills/list returns each skill's frontmatter and file list

Why it helps

  • Instructions live with the service they describe
  • Skill updates ship with the server

Example: GitHub MCP server

Proposed skills for potential future release:

  • address-pr-feedback
  • debug-ci
  • fix-dependabot
  • prepare-release
  • review-pr
  • security-audit
  • triage-issues
  • trigger-workflow

๐Ÿ”— Draft PR

๐Ÿ”— ext-skills

Agent plugins

An open standard for packaging skills and MCP servers into one portable plugin.

my-plugin/
โ”œโ”€โ”€ plugin.json
โ”œโ”€โ”€ skills/
โ”‚   โ””โ”€โ”€ skill-name/
โ”‚       โ””โ”€โ”€ SKILL.md
โ”œโ”€โ”€ mcp.json
โ””โ”€โ”€ com.github.copilot/
    โ””โ”€โ”€ hooks/
        โ””โ”€โ”€ hooks.json
  • plugin.json: names the plugin and the spec version it targets
  • skills/: Agent Skills, in the standard format
  • mcp.json: MCP servers to connect
  • Client-specific folders such as com.github.copilot/: optional extras like hooks; other clients ignore them

๐Ÿ”— agent-plugins.org

Skill, MCP server, or plugin?

Does the agent need live data or actions in another system?
yes →
MCP server
Does it need a repeatable procedure or team know-how?
yes →
Agent skill
Is the procedure tied to one server's tools?
yes →
Skill served over MCP
Do you want to share skills and servers as one package?
yes →
Agent plugin
These combine: a skill can call MCP tools, and a plugin can bundle both.
15 min

Exercise 4:Run agent skills in GitHub Copilot

GitHub repository: ๐Ÿ”— github.com/pamelafox/github-copilot-mcp-skills-workshop

Open full exercise: ๐Ÿ”— exercise4.md

Choose one or more activities:

  1. Inspect and run the project's /pr-summary-report skill.
  2. Inspect and run a built-in Copilot client skill.
  3. Install Matt Pocock's skills and try /codebase-design.
  4. Create and test a /quiz-question-reviewer project skill.

Next steps

Learn more: GitHub Copilot

๐ŸŽฅ VS Code + GitHub Copilot

Videos covering Copilot features and workflows in VS Code.

๐Ÿ”— GitHub Copilot Series

๐ŸŽฅ GitHub Copilot app

Meet the AI desktop assistant and see how it fits into your workflow.

๐Ÿ”— Meet the GitHub Copilot app

๐ŸŽฅ GitHub Copilot Day

Sessions and demos spanning the GitHub Copilot product family.

๐Ÿ”— GitHub Copilot Day

๐ŸŽฅ GitHub Copilot CLI

A beginner-friendly walkthrough of Copilot in the terminal.

๐Ÿ”— Getting started with Copilot CLI

Learn more: MCP

๐ŸŽ“ MCP for Beginners

A hands-on curriculum covering MCP concepts and development.

๐Ÿ”— Start learning

๐ŸŽฅ MCP Live

Rewatch sessions covering the latest MCP tools, patterns, and integrations.

๐Ÿ”— Watch the recordings

๐ŸŽฅ Python + Azure

A video series on building MCP servers with Python and Azure.

๐Ÿ”— Watch the series

๐Ÿงฉ MCP in VS Code

Learn how to configure and use MCP servers in VS Code.

๐Ÿ”— Explore the guide

Thank you

Questions?

Workshop repository:
๐Ÿ”— github.com/pamelafox/github-copilot-mcp-skills-workshop