Rna Agent
Guides

Skills and MCP

Install skill packages and MCP servers, assign them to projects, or just ask Rna to install them in a conversation.

Three states

The daemon manages the capability catalog; projects only store their own assignments. Installed to the catalog, enabled, and assigned to a project are three separate states. activate: true at install time enables it and assigns it to the current project; other projects gain nothing.

The skill catalog holds metadata only. The model reads a skill’s body and resources with skill_load when needed, instead of loading every skill into every turn.

Install from a conversation

In a project session with a real model, describe the source and purpose:

Install the full skill in /absolute/path/to/my-skill into this project, check the source and enable it, then read its references as needed and continue.

Foreground sessions always have five management tools, sharing one install service with the UI, CLI and HTTP API:

ToolPurposeChanges the project?
capability_listCatalog and current project assignmentsNo
capability_inspectCheck a source’s format or metadataNo, does not start MCP
capability_installInstall a full capabilityYes
capability_assignAssign to the current projectYes
capability_removeRemove from the project, or unregister an unused capabilityYes

After the current tool batch finishes, the SDK refreshes tools and the skill catalog before the next model request, so one turn can “install, read the new skill or call the new MCP, answer”. Background work does not carry these tools.

Install from the UI

Select a project, open Skills & tools → Install capability. Sources: local skill folder, Git skill, npm MCP server, MCP JSON import, or the official browser preset. “Check source” first, then “Install and enable” or “Install only”.

The browser preset finds an installed Chrome or Chromium, pins the official version, actually launches it and takes a screenshot before publishing. It needs no API key and never takes over your personal browser.

Install descriptors

{
  "kind": "skill",
  "id": "project-review-v1",
  "source": { "type": "local", "path": "/absolute/path/to/my-skill" },
  "activate": true,
  "reason": "Used for reviews in this project"
}

Copies the whole skill folder including references, scripts and assets; no script runs during install. .git and node_modules are skipped; symlinks, more than 10,000 entries or 32 MiB are refused.

MCP permissions

  • An explicit allowTools (including an empty {}) is the complete permission boundary.
  • Without a list, toolPermission: "exec" authorizes all tools discovered now; with neither, no tool is granted.
  • Tools the server adds later get no permission, and a server’s own readOnlyHint never replaces authorization.

stdio and Streamable HTTP are supported. Each stdio server is watched by a small guardian; if Rna is killed, it reclaims the process group it started.

Skill marketplaces

Rna can search and read public skill marketplaces, then go through the same check and install flow:

./rna marketplace search "pdf" --provider skills-sh --limit 5
./rna marketplace read skills-sh RESULT_ID

On this page