How to Install and Use xCloud AI Agent Skills

Updated September 25, 2026 · 7 min read

xCloud AI Agent Skills teach your AI assistant how xCloud works. Paste a GitHub URL and say “deploy this”, ask “install Ghost on my Frankfurt server”, “renew SSL for example.com” or “why did my last deploy fail?”, and the agent picks the right skill, previews what it will do, asks once, then finishes the job: it provisions, polls, checks the live URL, and diagnoses and retries failures. No endpoints to memorise, no SDK to wire up.

The skills pair with the xCloud MCP server, which gives the agent one tool per xCloud Public API operation. MCP is the connection; the skills are the know-how on top of it. If your agent cannot use MCP, the plugin carries a REST fallback that works with an API token.

The current release is v4.3 with seven skills. It is open source on GitHub under the MIT licence and free to use.

📸 Watch A Quick Walkthrough

The seven skills

You never name them. The agent picks the right one from what you ask.

Skill What it owns
xcloud:deploy Deploy anything: a GitHub, GitLab or Bitbucket URL, Docker Compose or Dockerfile apps, one-click apps, Git staging environments, new WordPress sites. Detect, dry run, approve, provision, verify, and diagnose and retry failures
xcloud:servers Servers: buy a server (plans, prices, provisioning), services install, enable and restart, Node.js and PHP versions, verified reboots, cron, firewall and Fail2Ban, sudo users, DNS checks
xcloud:sites Site lifecycle: status, backups (including Docker apps), staging, domains, cache, SSH, site cron, monitoring, site deletion
xcloud:wordpress Plugins, themes and updates, WP_DEBUG, magic login, site and team vulnerabilities, PageSpeed, broken links
xcloud:ssl SSL certificates: view, install, renew, status, delete
xcloud:billing Plan, invoices, bills, subscriptions, prices, paying an invoice, mailboxes and mail delivery
xcloud:account Current user, teams (multi-team), incident alerts, API tokens, Git and Cloudflare integrations, blueprints, health

Prerequisites

The MCP server is the fastest way to give any agent full xCloud control: OAuth sign-in in the browser, no token to store, and built-in confirmation before risky operations. Run this in your terminal:

claude mcp add xcloud --transport http https://app.xcloud.host/mcp

Then type /mcp inside Claude Code, choose Authenticate, and grant Read or Read & write on the xCloud approval screen. Since xCloud v2.8.8 you can tick several teams on that screen; the skills then pick the right team per request. Every client (Claude Desktop, Cursor, Codex, OpenCode, Hermes and others) is covered in How to Connect xCloud MCP to Your AI Agent.

Expected result: /mcp shows xcloud as connected, and “who am I on xCloud?” answers with your name, email and team.

Step 2: Install the skills plugin

Run these three commands inside Claude Code to add the xCloud marketplace, install the plugin and load it:

/plugin marketplace add xCloudDev/xcloud-agent-skills
/plugin install xcloud@xcloud-agent-skills
/reload-plugins

Expected result: Claude Code lists the xcloud plugin as installed. If you connected MCP in Step 1, you are done: no token to add.

Step 3: Check it works

Ask Claude:

Check my xCloud API connection.

Expected result: A green light with your account and team. If xCloud finds no connection, the skills offer the MCP connector first and only then guide you through a scoped token.

Step 4: Start asking

You describe what you want; the agent chains the steps.

Deploy https://github.com/acme/shop to my Frankfurt server.
Install Uptime Kuma on my Docker server and give me the URL.
Update all plugins on example.com, but back up first.
The last deploy of the API site failed. Diagnose it, fix the build command, and retry.
Audit example.com: is it up, is SSL healthy, any vulnerabilities, and how is performance?

If the agent ever reaches for the wrong area, name it: “Using xcloud:ssl, renew the cert for example.com.”

For a longer tour of what to ask, and how to write a prompt that works, read What You Can Ask xCloud MCP to Do.

Fallback: use an API token instead of MCP

Only needed when your agent has no MCP support, or for the two REST-only operations (API-token management and the /health probe), which the skills call through their bundled curl wrapper even when MCP is connected.

Create the token

In the xCloud dashboard open Settings → Developers → API Tokens and select Create New Token.

Name the token and choose the narrowest scopes that cover your use: read:servers and read:sites to look, write:servers and write:sites to change things, read:billing and read:addons or write:addons for billing and add-ons. Avoid full access unless you need token management. You can also grant the token several teams; see multi-team access.

Copy the token when it is shown. xCloud displays it only once.

Add it to Claude Code settings

Put the token in ~/.claude/settings.json (global) or a project-local .claude/settings.local.json that stays out of git, then restart Claude Code:

{ "env": { "XCLOUD_API_TOKEN": "your-token-here" } }

Do not paste a production token into a chat message: anything in a conversation can persist in history. Rotate tokens regularly and revoke any that were exposed.

Use the skills with other agents

  • Agent Plugins package. The repository ships a portable package of the same seven skills plus the xCloud MCP connection in the standard layout (plugin.json, mcp.json, skills/). Compatible clients today include ChatGPT and Codex, Cursor, GitHub Copilot, Kiro and VS Code; the client manages the OAuth sign-in. See the repository’s install guide.
  • Any agent with a skills directory. The skills are plain Markdown plus a skill-local bash/curl wrapper. Clone the repository, build the package and copy skills/* into your agent’s skills folder. Agents that support MCP load the root mcp.json; others use the REST wrapper with XCLOUD_API_TOKEN.
  • OpenClaw. Install from ClawHub; see OpenClaw skills and ClawHub on xCloud.

What the skills add on top of MCP

MCP alone already exposes every xCloud operation as a tool. The skills add the judgement around them:

  • Routing. Each skill declares what it owns and what it does not, so “renew the cert” lands on xcloud:ssl and not on a site tool.
  • Preview, then ask. A deploy is detected and dry-run first, the plan is shown, and the agent asks once before it provisions.
  • Polling and verification. Long jobs are polled to completion and the live URL is checked, rather than reported as “started”.
  • Diagnosis and retry. A failed deploy gets a diagnosis of the failing step and a corrected retry on the same site.
  • Safety guardrails. Backups before updates, no secrets echoed into summaries, scoped tokens on the REST path.

Frequently asked questions

Do I need the skills to use xCloud MCP?

No. The MCP connection alone gives your assistant every xCloud tool. The skills are an optional layer on top that teach the agent xCloud’s workflows: which tool to reach for, how to preview and confirm, how to poll a long job, and how to diagnose and retry a failed deploy.

Do I need an API token?

Not if you connect through xCloud MCP: sign in once in the browser and the skills use that connection. An API token is only the fallback for agents without MCP support, or for the two REST-only operations (token management and the health probe).

Which AI assistants do the skills work with?

The plugin installs into Claude Code. A portable Agent Plugins package of the same seven skills loads into ChatGPT and Codex, Cursor, GitHub Copilot, Kiro and VS Code, and the skills are plain Markdown, so any agent with a skills directory can use them.

Do AI Agent Skills cost extra?

No. The skills are open source under MIT and run on the xCloud MCP server or Public API that comes with your account. Your AI assistant may have its own usage cost from its provider.

Is it safe to let the assistant act on my account?

The skills act only with the access you granted: Read or Read and write on the MCP connection, or the scopes on a token. Risky operations such as creating, deploying, updating, rebooting, deleting and buying stop for your confirmation, and the skills preview a change before asking.

Next steps

If you have any questions or run into issues, feel free to reach out to our support team.