Announced 10 Oct 2026 · Sources checked
What did the 10 October changelog add?
The primary object is https://developers.cloudflare.com/changelog/post/2026-10-10-cloudflare-mcp-skills/. The page is titled “Cloudflare API MCP server serves Cloudflare skills,” dated October 10, 2026. Its description line is that the Cloudflare API MCP server serves Cloudflare skills through the Skills over MCP extension.
The body is two sentences. “The Cloudflare API MCP server now serves Cloudflare skills through the Skills over MCP extension.” Clients that support the extension “discover the skills with skills/list and read their files at skill://<name>/<path>.” To use them, “add https://mcp.cloudflare.com/mcp to an MCP client that supports the extension.” Those sentences are the changelog’s.
The changelog’s “Cloudflare skills” link is https://github.com/cloudflare/skills. The extension link is the Skills over MCP overview. The supporting-client link is the MCP client matrix. This is a protocol hook on an existing remote server, not a new model. It sits next to, and is not the same story as, Clef-omni on Workers AI on 9 October.

How do skills over MCP differ from a local skills folder?
A skill, in the Agent Skills specification we opened at agentskills.io, is a directory with a SKILL.md and optional supporting files. Hosts that already load filesystem skills look in directories such as ~/.claude/skills/ or ~/.codex/skills/. That path copies files onto the machine. It is not what the changelog announced.
Skills over MCP is an extension, identified as io.modelcontextprotocol/skills. A server that declares it must implement skills/list and skills/get. Skill files are ordinary resources: they are read with resources/read. The overview we opened is explicit that a resources/read of SKILL.md “does not itself activate a skill.” The host has to route that read through its own skill-loading path, verify bytes against the manifest, and apply any required approval. That is a different object from MCP tools versus resources, which splits actions from readable context, and from MCP prompts, which are reusable message templates.
The Agents docs page we opened on 10 October still describes a separate install: a Cloudflare Skills plugin that “bundles the Cloudflare MCP servers alongside contextual skills and slash commands,” plus npx skills add https://github.com/cloudflare/skills, plus copying folders into an agent’s skill directory. Those paragraphs are how-to for the Agent Skills filesystem path. They are not a substitute for skills/list on mcp.cloudflare.com.

What does the Cloudflare API MCP server already do?
The living page “Cloudflare’s own MCP servers,” last updated 10 October 2026, is the how-to around the changelog. It says Cloudflare runs managed remote MCP servers you connect with OAuth. New connections should use the Streamable HTTP endpoint at /mcp. The servers “support the new MCP 2026-07-28 Specification.” Historical /sse URLs remain aliases for the same handler and “do not serve the deprecated HTTP+SSE transport.”
The Cloudflare API MCP server, it says, “provides access to the entire Cloudflare API — over 2,500 endpoints across DNS, Workers, R2, Zero Trust, and every other product — through just two tools: search() and execute().” It uses a search-and-execute Code Mode pattern: the model writes JavaScript against a typed OpenAPI representation, and that code runs in an isolated Dynamic Worker sandbox. Cloudflare’s table on that page puts Code Mode at about 1,000 tokens against about 1,170,000 for native MCP with full schemas. Those token figures are Cloudflare’s. We did not measure a session.
Connecting still means adding https://mcp.cloudflare.com/mcp, then authorizing via OAuth and choosing permissions — or passing a Cloudflare API token as a bearer token for CI. That is account access, not a read-only catalog. For why a protocol connection is not a permission grant, stay on MCP explained. For why a hosted agent that can change state still needs a human gate, see agent approval gates.
| Path | Where it is described | What you add |
|---|---|---|
| Skills over MCP | 10 October changelog | https://mcp.cloudflare.com/mcp on a client that implements the extension; skills/list then skill://<name>/<path> |
| Filesystem Agent Skills plugin | Agents docs, last updated 10 October | /plugin marketplace add cloudflare/skills, npx skills add, or copy folders into ~/.claude/skills/ and peers |
What does a supporting client actually have to implement?
The Skills over MCP overview we opened says the published specification lives in the ext-skills repository and that SEP-2640 is Final. “SDK and host support is still being implemented; see the client support matrix and implementations list for current coverage.” The changelog’s third link is that matrix. We did not audit every row.
A server that declares the extension must also declare the resources capability. skills/list returns entries with a SKILL.md URI, unchanged YAML frontmatter, and a file manifest of URIs, SHA-256 digests, and byte sizes — or the string “dynamic” for generated content. skills/get looks up one skill by the URI of its SKILL.md. Hosts must support loading by URI even when a skill is absent from a list page.
Integrity rules on that overview are host-side. While a skill is loaded, the host keeps the entry, restricts reads to the retained manifest, and verifies raw size and digest before use. A changed file revokes persisted approval. Digests “establish consistency with the server’s manifest, not trust in its content.” Treat remote skill text as untrusted instructions, the same way you would treat any other fetched markdown.
What should a team check before pointing an agent at it?
Confirm the client you already use implements io.modelcontextprotocol/skills, not only base MCP. The changelog’s usefulness depends on that row. Then decide whether you want the remote catalog, the local plugin, or both. They are not substitutes.
OAuth scopes on mcp.cloudflare.com still apply to search() and execute(). Serving skills does not shrink that blast radius. If the agent can execute API calls, keep the token on the smallest role you would give a script. We did not create a token or complete an OAuth grant.
This changelog is also not Anthropic’s 9 October Managed Agents workflows, which is a hosted run with its own 1,000-agent lifetime cap. And it is not Together Link, which points coding agents at Together-hosted models. Keep the products in separate columns.
What did we not test?
We have not added https://mcp.cloudflare.com/mcp to a client, completed OAuth, called skills/list, or read a skill:// resource. We did not install the Cloudflare Skills plugin, run npx skills, or copy folders into a local skill directory. We did not open every product-specific Cloudflare MCP server listed on the docs table. Secondary write-ups that restate the changelog are not additional evidence.
Common questions
Did Cloudflare publish a blog post for this?
Not that we opened. The dated object is the 10 October changelog entry. The living Agents docs page was last updated the same day and describes the API MCP server and a separate filesystem skills plugin. Those are docs, not a newsroom launch.
If I already installed cloudflare/skills locally, do I have this feature?
Not on the pages we opened. Copying skill folders into ~/.claude/skills/ is the Agent Skills filesystem path. The changelog is about the API MCP server serving those skills over MCP to clients that implement skills/list and skill:// reads.
Does reading a SKILL.md activate it?
No. The Skills over MCP overview says resources/read is transport. A host activates a skill only through its own loading path, after verification and any required approval.
What to remember
If you already talk to Cloudflare through MCP, the 10 October changelog is a skills catalog on the same https://mcp.cloudflare.com/mcp endpoint — if your client implements the extension. Keep the filesystem plugin in its own column, and do not treat a raw resource read as a loaded skill.
Sources & further reading
How this story was made
Written by Kristian Kostov with AI assistance and checked against the linked sources. Company performance claims are attributed to the company. Analysis reflects AiLookout’s interpretation; we have not independently tested the products discussed. Cover photography is illustrative and does not depict the specific announcement or product.
Our editorial standards





