# Agents now pick their own plugins, skills and MCP servers

> An agent finds the plugin, skill or MCP server its task needs and connects it to its own card, with your approval for anything new; cards stay working while their subagents run, and subagent usage is counted once; a two-column add-card menu.

- URL: https://neurosquad.ai/en/blog/agents-equip-themselves/
- Published: 2026-10-05
- Publisher: NeuroSquad (https://neurosquad.ai/)

In NeuroSquad an arrow is a permission. Draw one from an agent to a Memory card and the agent gets `memory_*` tools; draw one to a skill or an MCP server card and it can use that. It is a clear model, but it puts one job on you: knowing in advance what each agent will need. In practice the agent is the first to find out — halfway through a task it turns out that the project’s decisions should survive the session, or that the documentation of a library would save ten guesses.

NeuroSquad 0.1.270 lets the agent do that part. It can see which **plugins, skills and MCP servers** it could have and **connect the one it needs to its own card**. Anything that isn’t installed yet still waits for your approval. Cards also stay **working while their subagents run**, and the tokens those subagents spend are **counted once, with their own share**. The add-card menu is now **two columns with everything in view**, and there is a long list of fixes. This is a Windows release; the Mac app stays on 0.1.230 for now and gets all of this with its next build.

## An agent that equips itself

Every agent card now has two more built-in tools. `neurosquad_catalog` lists what the agent could use: the plugins (Memory, Context7, Graphify, RTK, Caveman and the rest), the skills and MCP servers already installed on this computer, and — when the agent searches — matches from skills.sh and the official MCP registry. Each entry says what it is for, which tools it would give, and its state for this agent: already connected, on the canvas, available, not installed, needs settings, or simply not usable with that agent CLI or in a WSL or SSH workspace.

`neurosquad_equip` then adds the chosen one. If a matching card is already on the canvas, the agent only gets an arrow to it; otherwise a new card appears beside the agent, in its frame, with the arrow drawn. The same rules as for arrows you draw apply: a paused budget stops it, sensitive cards the agent didn’t create stay out of reach, and one agent can add at most eight cards of its own.

![The canvas: a new Memory (mem0) card above the Lead card with an arrow from Lead to it; Lead’s terminal shows the prompt “Keep the decisions we make here across sessions.”, “Called neurosquad” and the answer “Connected Memory to my card”; bottom right the notice Lead connected Memory (mem0) with Undo](https://neurosquad.ai/blog/agents-equip-themselves/equip-toast-en.webp)

*Lead connected Memory to itself. The notice in the corner has Undo, which removes the card it created. The model here is a scripted test server.*

You see each of these changes: a notice in the corner says which agent connected what, and **Undo** takes it back — the card if the agent created one, only the arrow if the card was already there. Plugins and things already installed connect at once and work in the same session; the agent can call the new tools in its very next step.

## Nothing new without your yes

Installing a skill or an MCP server means running someone else’s code on your computer, so an agent can never do it by itself. When it asks for something not yet installed, NeuroSquad shows a dialog with what would be installed: the package, where it comes from, the version and the exact pinned hash or commit, the license, its files and scripts, and the results of the security scans the catalog has. Only **Install and connect** installs it, through the same pinned installers as the catalog. **Deny**, or no answer within ten minutes, installs nothing, and the agent is told so.

![The dialog Install pdf?: Lead wants to add this skill to itself. Nothing is installed unless you allow it. Below, the skill’s description and a table with Package anthropics/skills/pdf, Source, Commit, Pinned hash, License, Files and Security scans, two warnings about scripts and a scan that reported a risk, and the buttons Deny and Install and connect](https://neurosquad.ai/blog/agents-equip-themselves/install-consent-en.webp)

*An agent asked for a skill that isn’t installed. The dialog comes up even in dangerous mode.*

The dialog comes up in dangerous mode too, and in canvas mode. A server that needs a key or other settings opens the catalog instead, since an agent can’t fill those in. If you would rather connect everything yourself, the workspace’s edit dialog has a switch, **Agents can add plugins, skills and MCP to themselves**. It is on by default.

## How an agent knows what to ask for

Tools only help if the agent thinks of them. So once per session, with its first prompt, an agent gets a short note: the two tools, the rule about installs, and the plugins and installed items that would work for it. The note is capped at 1200 characters, roughly 300 tokens, and it isn’t repeated later in the session. It reaches Claude Code, Codex and Qwen Code through their prompt hook, and OpenCode, Kilo Code, pi, omp and Gemini CLI through the same bridge that Memory already uses. Other agent CLIs still have the tools and their descriptions, just without the note.

One difference between CLIs showed up while testing. Some, like Codex, read their list of tools only once, at the start. For them the plugin and skill tools are now listed from the start, so equipping one works in the same session. A newly added MCP server’s own tools reach such a CLI only after the card restarts, and the agent is told that.

## Subagents: still working, counted once

Many agent CLIs can hand part of a task to a subagent — Claude Code’s Agent tool, OpenCode’s task sessions, Qwen Code’s agents. Recent versions of Claude Code start them in the background by default: the main agent answers “two reviewers are on it” and ends its turn while the subagents keep working. For NeuroSquad that turn end looked like the end of the work, so the card said **done** and rang while two subagents were still busy.

Now a card keeps track of the subagents its agent started. While any of them runs, the card stays **working**, and it finishes only when the whole job is done. A chip in the card’s header shows how many subagents are running, and its tooltip lists their types. If a subagent needs a permission, the question shows on its parent card with the subagent’s name in front. Claude Code, OpenCode, Kilo Code and Qwen Code report subagents this way.

![The Lead card working, with a chip showing 2 in its header and the tooltip 2 subagents, Subagents running: general-purpose ×2; Lead’s terminal shows two background agents launched, Payment error paths and Cart test gaps, and Waiting for 2 background agents to finish; on the right a Run Stats card measuring Lead’s run](https://neurosquad.ai/blog/agents-equip-themselves/subagents-en.webp)

*Lead started two reviewers in the background. The card stays working and shows them in its header.*

The second half is money. A subagent’s model requests are paid for like the agent’s own, so they belong to its card — and they must be counted exactly once. Checking every CLI, we found three places where that didn’t hold. Kilo Code adds a subagent’s cost to the message that started it, which was counted a second time. A forked Codex subagent copies its parent’s history into its own log, tokens included. And Hermes Agent’s child sessions were never credited to the card at all. All three are fixed.

![The same canvas after the run: Lead’s terminal shows each reviewer finishing and Lead summing up their findings; the card is Done; Run Stats, frozen at the finish, shows 1 prompt, 6 model requests, 7,200 input and 204 output tokens and 1:21 of working time](https://neurosquad.ai/blog/agents-equip-themselves/subagents-done-en.webp)

*Finished only after both reviewers were back. Run Stats counts their requests in the six.*

The totals in Usage, Run Stats and Agent Pulse include subagents, and Usage marks an agent’s row with **incl. N subagents**; its tooltip shows their tokens, requests and cost. For people who build their own cards, Card SDK 1.3 adds the same split: `agents.usage` gets a `subagents` part and a `mainOnly` option, and each request in `agents.timeline` says whether a subagent made it.

![The Usage section, By agent: the row Lead, marked incl. 2 subagents, in the workspace Checkout service with 6 requests, 7,200 input, 204 output and 7,404 total tokens](https://neurosquad.ai/blog/agents-equip-themselves/usage-en.webp)

*Usage keeps one row per card and says how much of it came from subagents.*

## The add-card menu, all of it at once

The add-card menu had grown into folded groups you had to open one by one. It is now two columns: agents on the left — installed CLIs first, marked with a green dot, then your saved agent templates — and cards on the right, with Skills, MCP and Plugins across the top. Everything is visible without scrolling in a 1280×800 window. The row under the pointer is explained next to the search field, typing filters both columns, and the arrow keys move up and down a column and across to the other one.

![The add-card menu open from the canvas toolbar: a search field with the hint Type to search, arrows to move, Enter to add; Skill, MCP server and Plugins on top; the Agents column with New agent… and nineteen agent CLIs; the Tools for agents, More cards and Make your own columns on the right](https://neurosquad.ai/blog/agents-equip-themselves/add-menu-en.webp)

*Agents on the left, cards on the right, nothing folded.*

## Fixes

- **Agent status**: a restarted CLI’s old process reporting late no longer moves the status, a prompt waiting in Claude Code’s own queue no longer ends in a false “finished”, and a pop-out window or the phone no longer plays a second sound.
- **Terminals**: your own `CLAUDE_CODE_*` settings, such as the Git Bash path, now reach Claude Code cards; only the markers of a parent Claude Code session are removed.
- **Plugins**: Memory search no longer waits behind a save, Memory and Context7 can no longer hold up a prompt, Caveman resends its rules when they didn’t arrive, and RTK uses exactly the `rtk` the agent’s shell will run.
- **Budget and browser cards**: Resume after the limit gives about another tenth of it and pauses again; deleting a browser card deletes its profile — cookies, logins and history.
- **SSH, WSL, dictation, account**: host keys are checked the way OpenSSH does, WSL survives `wsl --shutdown`, model downloads are checked against a pinned SHA-256, sign-in codes work only once for the session that asked for them, and the phone reconnects after the desktop restarts.

How agents equip themselves is described in [Skills, MCP and plugins](https://docs.neurosquad.ai/en/skills-mcp#self-equip). The full list of changes is in the [0.1.270 changelog](https://neurosquad.ai/en/changelog/#v0.1.270). NeuroSquad updates itself; a new install starts from the [download page](https://neurosquad.ai/en/download/).
