Join our Newsletter — 33% off our NHI Course
Home› FAQ› Architecture & Implementation› What is the difference between live MCP skills…
Architecture & Implementation

What is the difference between live MCP skills and agent plugins?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 30, 2026 Domain: Architecture & Implementation

Live MCP skills are server-owned instructions delivered at runtime over the connection, so connected clients can receive updates without reinstalling anything. Agent plugins are client-installed packages with a build-time distribution model. The difference matters because one is dynamic and runtime-driven, while the other is static and packaged for local installation.

Why live MCP skills and agent plugins behave differently

Live MCP skills are server-owned instructions delivered at runtime over an active connection, so the client can see updated behaviour without reinstalling or repackaging anything. Agent plugins are client-installed packages that follow a build-time distribution model. That means live skills are easier to change centrally, while plugins are easier to version, pin, and inspect as local artifacts.

The practical difference is control plane and change timing. With live MCP skills, the server can alter what the connected client can do during the session, which is useful for rapid updates but also means the runtime relationship matters. With agent plugins, the client keeps the installed package and its capabilities until the next update cycle, so the security and compatibility posture is tied to the installed release.

For practitioners, the key question is not just where the logic lives, but who can change it and when. If the capability must update instantly across many connected clients, live delivery is the better fit. If you need stronger packaging discipline, release management, and local reproducibility, a plugin model is usually the better operational choice.

Runtime delivery versus packaged installation

Live MCP skills are closer to a managed service contract: the server publishes instructions, and the client consumes them at connection time. That makes the model dynamic, but it also means behavior can vary between sessions if the server changes. Agent plugins are more like software you install and keep locally, so the execution context is stable until you upgrade the package.

This distinction affects troubleshooting and governance. A live skill can be fixed centrally, rolled back centrally, or changed centrally, which is efficient for coordinated environments. A plugin requires distribution to each client or endpoint, so the change path is slower but often more auditable at the individual installation level.

That also changes compatibility assumptions. Live MCP skills depend on the current server response and client interpretation at runtime. Agent plugins depend on the compatibility of the shipped package with the client runtime, so version drift, packaging quality, and local dependencies matter more than server-side instruction changes.

What the difference means for security and operational control

Security concerns shift with the distribution model. Live MCP skills place more weight on connection trust, server governance, and runtime authorization because the connected client is following instructions that can change during execution. Agent plugins place more weight on supply chain integrity, package provenance, and safe installation because the client is loading code or capabilities as a discrete artifact.

That does not mean one model is inherently safer. It means the failure modes differ. A live runtime model can be misused if a server changes instructions unexpectedly or if a client trusts a connection too broadly. A packaged plugin can be risky if the installed artifact is malicious, stale, overprivileged, or poorly maintained.

If you are evaluating one of these models for an agent workflow, MCP Security Guide is the right place to study the authorization side of runtime-delivered capabilities, while AI Coding Agents Security Guide is a better fit when the concern is packaged tooling, local execution, and developer-side exposure.

Risk and Threat Considerations

Live delivery concentrates trust in the runtime relationship, so a compromised or overly permissive server can influence connected clients immediately. Packaged plugins concentrate trust in installation, update, and provenance, so a malicious or tampered package can persist on the client until it is removed or replaced.

Failure mechanism: Runtime-delivered skills can change effective behaviour without a fresh installation event, while client-installed plugins can carry hidden capability or stale privilege into the local environment. Both create attack surface, but the attacker leverage point is different: session-time influence versus installed-artifact compromise.

Impact: The live model can widen blast radius if server-side changes propagate to many clients at once, while the plugin model can create durable exposure on endpoints that rarely update. In both cases, overtrusting the delivery channel turns a convenience feature into a control failure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP API Security Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseLive MCP skills and plugins both affect agent authority and runtime access.
ASI04 — Agentic Supply Chain VulnerabilitiesClient-installed plugins introduce packaged supply-chain exposure.
Recommendation — Constrain agent capability changes so privileged actions require explicit policy checks. Verify package provenance and update channels before installing agent plugins.
OWASP API Security Top 10API8 — Security MisconfigurationRuntime-delivered skills and installed plugins both depend on secure configuration.
Recommendation — Harden configuration defaults and validate exposed capabilities before deployment.
NIST SP 800-53 Rev 5SA-11 — Developer Testing and EvaluationPlugin and runtime capability changes need release-time validation.
CM-5 — Access Restrictions for ChangeLive server-delivered behaviour can change client actions without reinstalling.
Recommendation — Test capability changes before promoting them to production clients. Restrict who can modify agent capabilities and approve runtime changes.

Practitioner Guidance

What to verify: Decide whether your real control need is central runtime governance or local artifact governance. If the answer is runtime, verify server change control, client trust boundaries, and session-time authorization. If the answer is packaged distribution, verify signing, version pinning, update cadence, and uninstallability.

Common mistake: Teams often compare the two only on convenience and forget the operational consequence of where authority lives. A live skill is not just a faster plugin, and a plugin is not just a static skill, because the security ownership model changes with the delivery path.

Practitioner takeaway: Use live MCP skills when you need centrally governed, session-time behaviour, and use agent plugins when you need locally installed, versioned capability with tighter release discipline.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org