mcp-code-execution

v2026.09.24

Scaffold the code execution pattern for MCP-based agents. Use when agents call many MCP tools, intermediate data exceeds context, you need loops, or PII must stay out of context.

GitHub
Install command
npx skhub add laurigates/mcp-code-execution
Markdown
SKILL.md

MCP Code Execution Pattern

Expert knowledge for designing agent systems that generate and execute code to interact with MCP servers, instead of calling tools directly.

For the typed-wrapper code, the six key-pattern examples, and the project scaffolding steps, see REFERENCE.md.

When to Use This Skill

Use code execution when...Use direct tool calls / mcp-management when...
Designing agents that fan out across 10+ MCP servers or 50+ toolsInstalling or configuring one or two servers in .mcp.json
Intermediate results are large (>10K tokens) and would blow contextResults are small and all needed by the model
Workflows need loops, retries, or conditionals across tool callsLinear sequences of 2–3 tool calls
PII must not reach the model contextTool responses contain no sensitive data
Tasks benefit from state persistence across runsStateless, one-shot operations
You want agents to accumulate reusable skillsFixed, predefined workflows

Core Architecture

How It Works

Instead of loading all MCP tool definitions into context upfront, the agent:

  1. Discovers available tools by navigating a typed file tree
  2. Generates TypeScript/Python code that imports and calls typed wrapper functions
  3. Executes the code in a sandboxed environment
  4. Returns only filtered/summarized results to the model

This reduces token usage from O(all_tool_definitions) to O(only_relevant_imports).

File Tree Structure

project/
├── servers/
│   ├── google-drive/
│   │   ├── getDocument.ts
│   │   ├── getSheet.ts
│   │   └── index.ts          # Re-exports all tools
│   ├── salesforce/
│   │   └── index.ts
│   └── slack/
│       └── index.ts
├── skills/                    # Agent-accumulated reusable functions
├── workspace/                 # Persistent state between executions
├── client.ts                  # MCP client that routes calls to servers
└── sandbox.config.ts          # Execution environment configuration

Each MCP tool gets a typed wrapper function the agent imports (callMCPTool<T>("server__tool", input)); the agent writes ordinary code against those wrappers. See REFERENCE.md → Typed wrapper pattern.

Key Patterns

Six patterns make this efficient — each with a worked code example in REFERENCE.md → Key patterns:

PatternWhat it buys
Progressive tool discoveryNavigate servers/ on demand — ~150K tokens → ~2K (98.7% reduction)
Context-efficient filteringFilter large datasets in the sandbox; only a summary reaches the model
Native control flowLoops/retries/conditionals run in the sandbox, not as chained tool calls
PII tokenizationThe client tokenizes sensitive fields so PII never enters model context
State persistenceSave intermediate results to workspace/ for cross-execution continuity
Skill accumulationPersist reusable functions to skills/ for future executions

Scaffolding a New Project

The five-step scaffold — identify servers → generate typed wrappers → create the routing client → configure the sandbox → wire the agent loop — is detailed with code in REFERENCE.md → Scaffolding a new project. The agent loop becomes: explore servers/ → generate code → execute in sandbox → filtered output returns → decide done or iterate.

Security Checklist

ItemStatus
Sandboxed execution environmentRequired
Resource limits (CPU, memory, disk)Required
Network isolation (MCP servers only)Required
Execution timeoutRequired
PII tokenization in MCP clientRecommended for sensitive data
Audit logging of all executionsRecommended
Read-only access to servers/Recommended
Scoped write access to workspace/ onlyRecommended

Quick Reference

Token Impact

ApproachTool definitionsIntermediate dataTotal
Direct tool callsAll loaded upfrontPasses through contextHigh
Code executionOn-demand discoveryStays in sandboxLow

When NOT to Use This Pattern

  • Simple integrations with 1–3 MCP servers
  • All tool responses are small and needed by the model
  • No sensitive data in tool responses
  • Infrastructure complexity isn't justified (sandbox setup, monitoring)
  • Prototype or proof-of-concept stage

Reference

Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

MIT

Source path

agent-patterns-plugin/skills/mcp-code-execution

Default branch

main

Latest commit

1668324

Tree SHA

b2d4cc3