CHAPTER 10 · Skills, MCP, and Deterministic Computation · 2 / 8
MCP: a standard plug for external tools
The Model Context Protocol is an open standard for connecting external capabilities (databases, browsers, ticketing systems, your company's internal APIs) to an agent as named tools. An MCP server exposes a list of tools; the harness discovers them and makes them available to the model, usually with a prefix like mcp__server__action. The "Inside the Agent Harness" analysis shows the pattern: the harness asks the MCP connection manager to list all tools, converts each to the API's tool schema, and adds it to the available tools.
MCP is how the same harness lands in finance, life sciences, or an internal platform without forking the core CLI; you just point it at different MCP servers. But it carries two costs you already understand from earlier chapters. First, context: a server with dozens of tools could flood the context window with schemas. The fix is deferred schemas / tool search: only the tool names are loaded up front, and the full schema for a specific tool is fetched on demand when the agent wants it. Second, caching: recall from Chapter 5 that an early Codex bug enumerated MCP tools in an inconsistent order and silently broke caching, and that MCP servers can change their tool list mid-session (a tools/list_changed notification), which is an expensive cache-buster if honored carelessly. And from Chapter 7: MCP tools are not covered by the harness sandbox; they guard themselves. MCP is powerful and is exactly the kind of third-party dependency Chapter 13 warns about.