Teach the agent your work. Plug in your tools.
The AiServa AI Agent grows with skills, commands, plugins and MCP servers, at personal, organisation or platform level. Every addition is checked before it is used, keys stay on your server, and nothing in an add-on is ever run as code.

Skills load only when needed.
A skill is a SKILL.md file that tells the agent how your team does one kind of job. Keeping dozens of them costs almost nothing, because the model sees one line per skill until it picks one.
- 01
The Agent Sees a Menu
Each message lists only "name: description" for the skills you can use, up to 60 at a time.
- 02
It Asks for a Skill
When a task fits, the model replies [USE SKILL: name]. The server holds that reply back, so you never see it.
- 03
The Full Skill Loads
The server loads the full instructions and the model answers again, now following your procedure.
You can also load one directly: type / to open the picker, which lists skills and commands together. A personal skill wins over an organisation skill with the same name. When the agent drafts a new skill for you, it shows it as a card, and it is saved only when you press Save Skill.
Example SKILL.md
A Skill Library, reviewed before anyone uses it.
Open skills are useful and risky: a skill is text the model will follow. The Skill Library imports skills that follow the open agentskills.io format, and checks each one before a Platform Admin can approve it.
Pinned Sources
A GitHub or skills.sh address pinned to one commit, or an uploaded SKILL.md or zip. Up to 40 files per skill, 200 KB per file, 2 MB unzipped. Scripts, assets and binaries are dropped and never run.
Licence Allow-List
Accepted: MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC, 0BSD, Unlicense, CC0-1.0 and CC-BY-4.0. Refused: GPL-family, MPL, EPL, SSPL, BUSL, non-commercial, share-alike, no-derivatives and proprietary licences. A LICENSE file decides first.
Draft Until Approved
A new import waits as Draft. A newer upstream version waits as Pending review, so an approved skill never changes under you. Each person then adds approved skills in Settings. The library starts with the AiServa Starter Pack: 19 MIT-licensed business skills written by VYROX, from meeting minutes and SOPs to risk registers and quotation cover letters.
Blocking Findings
A skill with any of these can never be approved.
- Hidden or bidirectional Unicode characters
- "Ignore previous instructions" patterns
- Requests to reveal the system prompt
- Exfiltration, keylogger or credential-theft wording
- Requests to send passwords, keys, cards or one-time codes
- Base64 blobs of 200+ characters and data: addresses
- "You are now..." identity changes
Warnings for the Reviewer
Shown so a person decides with the facts in front of them.
- Shell or install commands
- References to scripts
- Coding-agent tool names
- "Don't tell the user" wording
- External links
Skills you write or add.
Commands: your prompts, one slash away.
A command is a saved prompt. Type /name and what follows it replaces $ARGUMENTS in the prompt. The nearest layer wins: personal, then organisation, then platform, and a command shadows a skill with the same name.
Limits: title 80, description 300 and prompt 8,000 characters; 100 personal, 200 organisation and 200 platform commands.
Plugins: add a set in one step, remove it cleanly.
A plugin bundles skills, commands and MCP servers that work together. Adding it writes each part into the place it normally lives and records exactly what was created, so removing it takes away exactly that and nothing else. Skills, commands, MCP servers and ready-made memory packs can also be added one by one.
Built-In Plugins
Meeting Assistant (minutes, action items, follow-up email), Writing Assistant (summarize, reply, translate, explain) and Developer Research (DeepWiki and Context7 plus a /library-docs command).
Built-In MCP Servers
DeepWiki, Context7 and Hugging Face for reading public sources, and GitHub and Stripe, which ask before every use.
A Plugin Holds
Up to 30 skills, commands and MCP servers. A memory pack is added on its own and holds up to 40 entries of 600 characters each.
A Plugin File Is Data, Never Code
Plugins, commands and MCP servers travel as a JSON file in the aiserva-app/1 format, up to 200 KB. It is read and checked, never executed. MCP servers inside must use https, and state whether a key is needed and whether they ask before use.
Export any plugin to share it with another organisation. The export never includes MCP server keys; the person adding it types their own.
Commands and plugins.
MCP servers, with the keys kept home.
The Model Context Protocol lets the agent use tools on another service. Add an MCP server's https address, with a key if it needs one, and its tools join the agent's toolbox for the people allowed to use MCP servers.
Ask Before Every Use
For services that can change data. AiServa Desktop asks you before each call; the web agent leaves these out.
No Need to Ask
For read-only sources. The web agent can use these on its own, one tool call at a time.

Any single tool of an MCP server can be switched off. MCP servers can be personal, for the organisation or for the platform; the nearest one is used first.
- Transport
- Streamable HTTP over https only, protocol version 2025-06-18. Local stdio servers are not run by the portal.
- Network Guard
- Every call passes the SSRF guard: private and internal addresses are refused and redirects are never followed.
- Timeouts
- Connect 8 seconds, handshake and tool list 20 seconds, a tool call 120 seconds.
- Size Caps
- Up to 60 tools per MCP server; each result is cut to 30,000 characters before the model sees it.
- Authentication
- A Bearer key or a custom header name. The key is sealed at rest and never sent to the browser or desktop.
- Rights
- Only people with the MCP Servers right see their tools, and every call is checked on the server.
MCP servers, with their health.
The agent in your own Chrome.
The AiServa Browser Controller extension lets the AI Agent work in a side panel of your own Chrome, on sites where you are already signed in. It is a Manifest V3 extension for Chrome 120 or later, downloaded from your AiServa portal. It is not listed on the Chrome Web Store.

- 01
Pair With a Code
The portal shows an 8-character one-time code, valid for 10 minutes and stored hashed. The extension trades it for its own token; your sign-in cookie is never used.
- 02
Give It a Task
The agent plans each step and the extension carries it out in your tab, reporting back after every step.
- 03
Stay in Control
You are asked Allow or Skip before any click that could buy, pay, send, submit or delete. Stop ends the task at once.
Act or Ask
Act lets the agent do the task in your tabs. Ask only reads the page and answers, so it cannot click or type anything.
Automatically or Manually Approve
Automatic is the default, and anything involving money or flagged as consequential still asks first. Manual shows the plan and asks before each change, with Decline, Allow Once, Allow for This Site or Allow for All Sites.
Mention Tabs
Type @ to bring up to 4 open tabs into the task, or right-click a page and choose Ask AiServa About it.
Sees the Page
When your Main Model can read images, the extension sends a small picture of the page along with its text, so the agent can work on pages that are mostly graphics. You can turn this off in Settings.
Upload Files
Attach up to 5 files of 10 MB each, 25 MB in all, and the agent can choose them in a file field. It asks first unless your task said to upload or attach.
Record a Workflow
Do a job once by hand, and it is saved as a shortcut you run by typing a slash. Passwords and secrets are never recorded.
Schedules and Shortcuts
Run a task every hour, day, week or month while Chrome is open and connected, or save a prompt as a shortcut. Scheduled tasks always run automatically.
History Across Devices
Your past browser tasks are listed on every device you paired, with passwords removed.
Blocked Sites
Sites you block are refused by the server itself, not just by the extension.
What It Can Do
Guard Rails
- Card numbers, one-time codes and file fields are never filled. Passwords are typed only if you turn on Let the AI Sign In for Me.
- At most 30 steps per minute; a task stops after 6 identical steps in a row.
- The server enforces your organisation's site policy on every step and never trusts the extension.
The Same Add-Ons in AiServa Desktop
AiServa Desktop receives your organisation's tools and MCP servers over MCP, and asks you before any MCP server set to Ask Before Every Use. No keys are stored on the laptop.
Skills, Plugins and MCP Server Questions
What is a skill in AiServa?
A skill is a SKILL.md file: a name, a one-line description and written instructions for one kind of job. The AI Agent sees only the name and description of each skill, and loads the full instructions only when a task needs them. Skills can be personal, for the whole organisation, or for the whole platform.
What is the difference between a skill and a command?
A skill is chosen by the agent when a task fits its description. A command is a saved prompt you run yourself by typing /name, with whatever you type after the name filled in where the prompt says $ARGUMENTS.
Can we import skills from GitHub or skills.sh?
Yes, through the Skill Library. A Platform Admin imports a skill from a GitHub or skills.sh address pinned to one commit, or uploads a SKILL.md or zip. Each import is licence-checked and scanned for prompt injection, and nobody can use it until it is approved.
Does AiServa run the scripts that come with a skill?
No. Scripts, assets and binary files are dropped on import. AiServa never runs a skill's code; only the written instructions are used.
What is an MCP server?
MCP, the Model Context Protocol, is an open standard that lets an AI agent use tools on another service. In AiServa you add the https address of an MCP server, with a key if it needs one, and its tools become available to the AI Agent and AiServa Desktop.
Where are MCP server keys kept?
On the AiServa server, sealed at rest. A key is never sent to the browser or to the desktop app, and exporting a plugin or an MCP server never includes its keys.
Can an MCP server act without asking?
Only if you set it to No Need to Ask. MCP servers that can change data should be set to Ask Before Every Use: the AI Agent then asks the person each time, on the web and in AiServa Desktop, and a scheduled task never uses them. Individual tools of an MCP server can also be switched off.
Is the AiServa Chrome extension on the Chrome Web Store?
No. It is downloaded from your AiServa portal and paired with a one-time code. It works in a side panel of your own Chrome and never fills card or one-time-code fields; it types a password only if you turn on Let the AI Sign In for Me.
Bring your team's way of working.
Write your procedures as skills, add the MCP servers you need and add plugins from the ready-made list, all in your own workspace. Free for 14 days.