I’ve been digging into how tools actually work in modern AI coding setups (like Claude Code), and here’s the simplest way to understand the landscape:
1. Plugins vs skills.md
skills.mdis just context — docs, conventions, instructions- Plugins are capabilities — they can execute code, call APIs, and interact with real systems
skills.md = “what the AI knows”
Plugins = “what the AI can do”
2. Plugins vs MCP servers
- A plugin is usually a single tool
- An MCP server (via the Model Context Protocol) is a system that provides many tools
Plugin = one tool
MCP server = toolbox
3. Where the actual code lives
A key realization:
- Plugins don’t always contain the real logic
- They often just call external services or local scripts
That’s why you sometimes only see .md files in repos—the real execution might be:
- running locally
- on a private server
- inside an MCP backend
4. Local vs SSH environments
Running AI tools locally vs on a remote server doesn’t change token usage much—but it changes risk:
- Local → safer, limited damage
- Server (via SSH) → powerful, but mistakes can be costly
Treat it like giving an AI shell access: use guardrails.
5. The big mental model
skills.md→ static knowledge- Plugins / MCP → live interaction with real systems