Catalog and installing
Skills, MCP & plugins is one window with four tabs: MCP servers, Skills, Plugins and Installed. Open it from the sidebar (Integrations → Skills, MCP & plugins), or from an empty MCP or skill card with Browse — then whatever you install lands on that card. The add-card menu’s Plugin… entry opens it on the Plugins tab.
Search
Results appear as you type. The whole catalog is kept on your computer and refreshed in the background, so search is instant and works offline.
- MCP servers come from the official MCP Registry — every server published there. Filter by how it runs: Local (a package that runs on your computer), Remote (a service on the internet), and No setup (nothing to fill in).
- Skills come from skills.sh, the most popular directory of agent skills. The most installed come first; while you are online, its own search is merged in with install counts.
- Installed is your library: everything on this computer, with settings, updates and uninstall.
Install an MCP server
Many servers can run several ways — an npm package (needs Node.js), a PyPI package (needs uv or Python), a Docker image (needs Docker), or a remote service over HTTPS. Ways NeuroSquad can’t run yet are shown greyed out, with the reason.
Keys and tokens (a Figma token, an API key) go into password fields. They are encrypted with your system’s keychain and never shown to agents — the agent only gets the tools.
The exact commands, the package and its pinned version, and the names of the settings it receives. If a Docker image asks for access to your files, network or devices, you get a warning.
Tick the box and press Install. The output streams below the button. NeuroSquad then starts the server once to list its tools, and it is ready.
Everything goes into NeuroSquad’s own data folder — its own copy of each package, its own
Python environment. Nothing is installed globally, and your ~/.claude, ~/.codex and other
agent settings stay untouched. Docker images are the exception: they live in Docker, as always.
After installing, open it in Installed to:
- Test — start it again and re-read its tools.
- Show its log — what the server printed, when it won’t start.
- Sign in / Sign out — for remote servers that use your account (OAuth). The login page opens in your browser; the tokens are stored encrypted.
- Change its settings — a saved key stays saved unless you type a new one.
- Uninstall — removes its files, settings and saved keys. Cards that used it stay on the canvas and ask for another one.
A server starts only when an agent first needs it, is shared by every agent connected to it, and stops after ten minutes without use.
Install a skill
You get its SKILL.md rendered in full, its files and size, its license, and the security
scans skills.sh publishes (Snyk, Socket and others).
If the skill ships scripts, you’re told: an agent following the skill may run them.
Tick “I read this skill” and press Install. What gets installed is exactly what you just read — if the skill changed upstream meanwhile, you’re asked to look again.
In Installed you can Update a skill when a newer version appears, Open folder to see its files, or Uninstall it.
Add a plugin
Plugins are built into NeuroSquad — nothing is downloaded to list them. Each one is a card that changes how the agents connected to it work; the first is the RTK-AI Token Saver, which compresses the output of their shell commands.
- Choose Plugin… in the add-card menu (typing
tokenorrtkin the menu’s search finds it too), or open the Plugins tab of the catalog. - Pick a plugin: you see what it does, how to use it and which agents it works with.
- Press Add to canvas. The card appears on the canvas of the workspace you opened the menu in (from the sidebar: the workspace on screen). Draw an arrow from an agent to it.
Safety
- Everything from a catalog is third-party. An MCP server is a program with the rights of your user account, or a web service your agents talk to. Install what you’d install anyway.
- Skill text becomes agent instructions. A skill can tell an agent to do anything — read it before you install it; the catalog shows it in full for that reason.
- Remote servers are HTTPS only. Keys never appear on a command line or in a log.