About me
Pamela Fox
Principal Cloud Advocate at Microsoft / GitHub
Formerly: UC Berkeley, Coursera, Khan Academy, Google
About you
Turn to your neighbor and introduce yourself:
Name
Location
What sessions have you liked so far at the conference?
What's your favorite coding agent or model?
Make up a new meaning for "MCP " (e.g. "M ore C offee P lease")
Today's agenda
Time Format Activity
11:00โ11:15 Welcome Introductions, GitHub Copilot, and Codespaces
11:15โ11:25 Exercise Set up environment and GitHub Copilot
11:25โ11:45 Presentation MCP: Model Context Protocol
11:45โ12:00 Exercise Connect GitHub Copilot to an MCP server
12:00โ12:10 Presentation Authenticated MCP servers
12:10โ12:30 Exercise Connect GitHub Copilot to GitHub MCP server
12:30โ12:40 Presentation Agent skills
12:40โ12:55 Exercise Run agent skills in GitHub Copilot
12:55โ1:00 Presentation Next steps
GitHub Copilot, wherever you work
VS Code Chat and agent mode in your editor, right next to your code.
Copilot CLI An agent in your terminal that reads files and runs commands.
Copilot app A standalone app for working with Copilot outside the editor.
Cloud agents Assign a task on GitHub, and Copilot works in the cloud and opens a pull request.
Today, you'll use either VS Code, Copilot CLI, or the Copilot app. Try Cloud Agents on your own later.
10 min
Exercise 1: Set up environment and GitHub Copilot
GitHub repository: ๐ github.com/pamelafox/github-copilot-mcp-skills-workshop
Open full exercise: ๐ exercise1.md
Exercise steps:
Fork the workshop repository into your account.
Choose Codespaces, a Dev Container, or a local environment.
Install dependencies and verify Python.
Open Copilot in VS Code, CLI, or the Copilot app.
Confirm that Copilot recognizes the workshop repository.
MCP: Model Context Protocol
AI agents
Agent loop
User query
LLM
Goal
Tools
An AI agent uses an LLM to run tools in a loop to achieve a goal .
Agents are often augmented by:
Context from files, docs, or databases
Memory across a session or project
Human approvals and feedback
๐ Simon Willison on defining agents
AI agents are used on a daily basis
Coding agents GitHub Copilot ยท Claude Code ยท Codex ยท Pi
Chatbots ChatGPT ยท M365 Copilot ยท Gemini
Assistants OpenClaw ยท Hermes ยท Meta Muse ยท Grok Bot
The agentic loop in action
Agent loop
User query
LLM
Goal
Tools
User Can I reorder my last bakery order for pickup today?
LLM find_customer("Pamela")
Tool result customer_id = "cust_42"
LLM get_last_order("cust_42")
Tool result items = [croissant, baguette]
LLM check_inventory(items)
Tool result croissant yes; baguette sold out
LLM find_substitute("baguette")
Tool result substitute = sourdough
Answer I can reorder it with sourdough instead. Want me to place it?
The key point is that the model cannot plan every call up front. It needs the customer ID before it can fetch the last order, the order items before it can check inventory, and the sold-out item before it can look for a substitute.
Agents rely on LLM tool-calling
LLMs have been trained to know how to "call tools".
LLM sees the available tools and their descriptions.
LLM suggests a tool name and arguments .
Agent runtime runs the actual code.
Tool result is sent back to the LLM as context.
LLM decides whether to call another tool or answer.
The model does not execute the tool. The runtime does.
User request
LLM
suggested tool call
get_last_order("cust_42")
Agent runtime executes tool
tool result
items = [...]
Emphasize the security and architecture boundary: the LLM produces a structured request for a tool call. The application, framework, or MCP client decides whether to allow it and runs the function. Then the result is added to the conversation for the next model step.
MCP: Model Context Protocol
MCP is the open standard that tells agent runtimes how to discover and connect to the tools they can call .
๐ค AI agent
๐๏ธ Database
๐ง Emails
GitHub
MCP
MCP
MCP
๐ MCP specification: modelcontextprotocol.io
MCP architecture
MCP Host
Example: GitHub Copilot
MCP Client A
MCP Client B
MCP Server A
MCP Server B
Tools
Prompts
Resources
Tools
Prompts
Resources
MCP
MCP
MCP hosts like VS Code contain MCP clients that connect to servers. Servers expose tools (functions the LLM can call), resources (read-only data), and prompts (instruction templates).
MCP client/server request flow
MCP Client
MCP Server
โ Discover tools
{"method": "tools/list"}
{"tools": [{"name": "get_product", "description": "...", "inputSchema": {...}}, ...]}
โก Call a tool
{"method": "tools/call",
"params": {"name": "get_product", "arguments": {"id": 1}}}
{"content": [{"type": "text", "text": "Product: Widget (id=1), $9.99"}]}
MCP uses JSON-RPC 2.0. The tools/list request returns tool schemas (name, description, inputSchema) that the LLM uses to understand what's available. The tools/call request invokes a specific tool with arguments and receives structured content back.
MCP clients
Support for MCP features varies across MCP hosts:
๐ caniuse.dev/host-compare
Avoid treating MCP support as a single checkbox. Use caniuse.dev for a current comparison, then verify the client version and configuration your audience will use.
Configure VS Code with public MCP server
Add to .mcp.json
{
"mcpServers": {
"microsoft-learn": {
"type": "http",
"url": "https://learn.microsoft.com/api/mcp"
}
}
}
Or install from Extensions
Search @mcp in the Extensions view:
Demo this live in VS Code. Show both ways to add a server, then show the tools in Copilot Chat with approval prompts.
Configure Copilot CLI with public MCP server
Add remote servers to your Copilot CLI user configuration.
1. Add the server
copilot mcp add --transport http microsoft-learn https://learn.microsoft.com/api/mcp
2. Verify the server
Start Copilot CLI:
copilot
Then run:
/mcp show microsoft-learn
Configure Copilot app with public MCP server
1
Open Customize โ MCP โ Add server โ Add custom server .
3
Select HTTP as the server type.
4
Enter the server URL:
https://learn.microsoft.com/api/mcp
6
Confirm the server shows as enabled and loaded with a green check mark.
Adding an MCP server is a trust decision
An MCP server gives the agent new abilities, and it acts with your access.
๐ฅ๏ธ Who runs it? Local servers run code on your machine. Remote servers see every request you send.
๐ง What can it do? Some tools only read. Others change files, repositories, or shared services.
๐ฅ What comes back? Tool descriptions and results are untrusted input that can steer the agent.
You exercise your control at two moments: when you connect a server, and each time a tool is called.
Approving a tool call
1
2
3
4
1
Which tool? A write tool deserves more scrutiny than a search.
2
What arguments? Read exactly what will be sent.
3
What changes? Remote state means other people will see it.
4
For how long? Session approval skips future prompts. Skip anything surprising.
Trusting a server to start is not blanket approval for every action. Approval behavior differs by host and user settings.
Authenticated MCP servers
How MCP servers restrict access
The server decides how you prove access. You'll see one of these:
Private network
Client
MCP
server
Private network
The server is only reachable from inside a company network or VPN.
You: connect from the right network. No sign-in prompt.
Client
key
header
MCP
server
Key-based access
You paste an API key or token, and the client sends it in a header.
Watch out: keys can leak. Never commit them to .mcp.json.
Client
Auth
server
MCP
server
login
token
bearer token
OAuth-based access
You sign in through the browser, and the client stores a token for you.
Example: GitHub MCP, which also accepts a personal access token.
As a user, you don't choose the model; the server does. Private-network servers just work when you're on the network. Key-based servers need a secret you paste in, which you must keep out of source control. OAuth servers open a browser sign-in, and the client keeps the token for you.
What happens when you sign in
User
MCP Client
Authorization Server
MCP Server
Starts the server or calls a tool
Redirects to AS with authorization request
Presents authentication prompt
Enters credentials
Authenticates user and
validates client registration
Displays consent page for client
Grants consent
Issues authorization code
Exchanges code for access token
Returns access token
MCP request + access token
Authenticated result or error
This is what happens behind the browser pop-up when you select Start on an authenticated server. You only see the sign-in and consent pages. The client handles redirects and token exchange, then attaches the token to every MCP request.
Every request carries your token
After sign-in, the client sends your token with each tool call:
MCP Client
MCP Server
Verifies the access token
and returns results scoped
to that signed-in user.
MCP
Authorization: Bearer <access_token>
{
"jsonrpc": "2.0",
"method": "tools/call",
"params": {
"name": "list_issues",
"arguments": { "repo": "..." }
}
}
MCP
{ "jsonrpc": "2.0",
"result": { "content": [
{ "title": "Fix quiz bug" }, ...
] } }
The request is a normal MCP tools/call, plus an Authorization header with your token. The server checks the token and returns only what your account can see.
Authentication vs. authorization
Authentication Proves who you are, usually with OAuth in the browser. Some clients also accept a personal access token.
GitHub example: your GitHub account, plus any org SSO policy.
Authorization Decides what each call may read or change, based on your account's permissions.
GitHub example: the repositories and orgs you can access.
The agent can do anything your account can do, within the access you granted.
GitHub MCP server
GitHub's official MCP server connects agents to the GitHub platform.
Remote: hosted by GitHub at https://api.githubcopilot.com/mcp/
Local: run it with Docker or a binary
Sign in: OAuth or a personal access token
GitHub groups its tools into toolsets , for example:
Repositories repos
Browse code, search files, read commits
Issues & PRs issues pull_requests
Create, triage, review, and update
Actions actions
Check workflow runs and build failures
Security code_security dependabot
Review code scanning and Dependabot alerts
Toolsets are a GitHub server feature, not part of the MCP spec. The default set is context, repos, issues, pull requests, and users. Copilot CLI starts read-only. Exercise 3 uses issues, repos, and pull requests.
Authenticated servers can expose write tools
Read and write tools carry different kinds of risk.
๐ Read Can expose private source or metadata Can ingest untrusted issue text Still deserves review Example: get_file_contents
โ๏ธ Write Changes shared state Can notify or affect other people Verify target and payload Example: create_pull_request
Authenticated does not mean approved. Remember: You can configure agents to require approvals for all write tools.
20 min
Exercise 3: Connect GitHub Copilot to GitHub MCP
GitHub repository: ๐ github.com/pamelafox/github-copilot-mcp-skills-workshop
Open full exercise: ๐ exercise3.md
Exercise steps:
Connect GitHub MCP with authenticated tools.
List and choose an open quiz issue.
Run and repair the quiz locally.
Commit the focused change to your fork.
Open a pull request to the workshop repository.
Different stages use different tools in the same agent loop. GitHub MCP handles the remote research, commit, and pull request; local editor and terminal tools handle the edit and test.
What is an agent skill?
A folder with SKILL.md instructions, plus optional scripts, references, and assets.
Folder layout
pdf-processing/
โโโ SKILL.md
โโโ scripts/
โ โโโ extract.py
โโโ references/
โ โโโ REFERENCE.md
โโโ assets/
SKILL.md
---
name: pdf-processing
description: Extract PDF text, fill forms,
merge files. Use when handling PDFs.
---
# PDF processing
1. Run scripts/extract.py on the file.
2. See references/REFERENCE.md for
form field details.
๐ agentskills.io
Agent Skills is an open format, originally from Anthropic, supported by GitHub Copilot, VS Code, Claude Code, Codex, and many other agents. The frontmatter needs a name and description; the description tells the agent when to use the skill. The body is plain Markdown instructions, and the optional folders hold code, docs, and templates the agent loads only when needed.
How coding agents run skills
1. Discover
Only each skill's name and description are in context.
2. Activate
When a task matches a description, the agent reads the full SKILL.md.
3. Execute
Scripts, references, and assets are loaded only as needed.
Well designed skills are activated only when needed - not over-activated or under-activated.
This is progressive disclosure, as described in the Agent Skills spec. Exact behavior varies by client, and many clients also let you invoke a skill directly, for example with a slash command.
Where skills live
Project level
.agents/skills/pr-summary-report/SKILL.md
Committed with the repository and shared with everyone who works on it.
Copilot also reads .github/skills/
User level
~/.agents/skills/my-skill/SKILL.md
Available across all of your projects.
Copilot also reads ~/.copilot/skills/
Third-party skills
Option 1: GitHub CLI
gh skill install mattpocock/skills
Option 2: skills CLI
npx skills add mattpocock/skills
Both let you choose where to install: project or user level, and for which agents.
Third-party skills run with agent permissions. Review their instructions and scripts before invoking them.
Skills over MCP
An official MCP extension lets servers ship skills alongside their tools.
How it works
Server declares the skills extension
skills/list returns each skill's frontmatter and file list
Why it helps
Instructions live with the service they describe
Skill updates ship with the server
Example: GitHub MCP server
Proposed skills for potential future release:
address-pr-feedback
debug-ci
fix-dependabot
prepare-release
review-pr
security-audit
triage-issues
trigger-workflow
๐ Draft PR
๐ ext-skills
The extension ID is io.modelcontextprotocol/skills. It builds on the existing Resources primitive. A server lists skills with their name, description, and a manifest of files with digests. The host loads SKILL.md only when a skill is selected, verifies it against the manifest, and pulls supporting files on demand. Approval binds to the manifest, so a changed file requires fresh approval.
Agent plugins
An open standard for packaging skills and MCP servers into one portable plugin.
my-plugin/
โโโ plugin.json
โโโ skills/
โ โโโ skill-name/
โ โโโ SKILL.md
โโโ mcp.json
โโโ com.github.copilot/
โโโ hooks/
โโโ hooks.json
plugin.json: names the plugin and the spec version it targets
skills/: Agent Skills, in the standard format
mcp.json: MCP servers to connect
Client-specific folders such as com.github.copilot/: optional extras like hooks; other clients ignore them
๐ agent-plugins.org
Plugin authors write the package once, and each compatible client decides how to install it, which permissions to grant, and how it appears in the UI. The GitHub MCP server repository already ships an agent-plugin package.
Skill, MCP server, or plugin?
Does the agent need live data or actions in another system?
yes →
MCP server
Does it need a repeatable procedure or team know-how?
yes →
Agent skill
Is the procedure tied to one server's tools?
yes →
Skill served over MCP
Do you want to share skills and servers as one package?
yes →
Agent plugin
These combine: a skill can call MCP tools, and a plugin can bundle both.
15 min
Exercise 4: Run agent skills in GitHub Copilot
GitHub repository: ๐ github.com/pamelafox/github-copilot-mcp-skills-workshop
Open full exercise: ๐ exercise4.md
Choose one or more activities:
Inspect and run the project's /pr-summary-report skill.
Inspect and run a built-in Copilot client skill.
Install Matt Pocock's skills and try /codebase-design.
Create and test a /quiz-question-reviewer project skill.
Learn more: GitHub Copilot
๐ฅ VS Code + GitHub Copilot
Videos covering Copilot features and workflows in VS Code.
๐ GitHub Copilot Series
๐ฅ GitHub Copilot Day
Sessions and demos spanning the GitHub Copilot product family.
๐ GitHub Copilot Day
Learn more: MCP
๐ MCP for Beginners
A hands-on curriculum covering MCP concepts and development.
๐ Start learning
๐ฅ MCP Live
Rewatch sessions covering the latest MCP tools, patterns, and integrations.
๐ Watch the recordings
๐ฅ Python + Azure
A video series on building MCP servers with Python and Azure.
๐ Watch the series
๐งฉ MCP in VS Code
Learn how to configure and use MCP servers in VS Code.
๐ Explore the guide