# Mcp Elicitations

> Implement and test FastMCP user elicitation and MCP Apps interaction patterns with explicit accept, decline, cancel, validation, and security behavior.

- **Type:** Skill
- **Install:** `agentstack add skill-batteryshark-skill-tap-mcp-elicitations`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [batteryshark](https://agentstack.voostack.com/s/batteryshark)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [batteryshark](https://github.com/batteryshark)
- **Source:** https://github.com/batteryshark/skill-tap/tree/main/skills/development/mcp/mcp-elicitations

## Install

```sh
agentstack add skill-batteryshark-skill-tap-mcp-elicitations
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Build Interactive FastMCP Workflows

1. Decide whether the interaction belongs in ordinary tool arguments, protocol elicitation, or an MCP App. Read [references/interaction-models.md](references/interaction-models.md).
2. Use `ctx.elicit()` for server-initiated, client-mediated structured input during a tool call. Define the response with supported scalar types or a Pydantic model and handle accept, decline, and cancel explicitly.
3. Use an action-only elicitation or the Apps Approval provider for a human checkpoint. A UI confirmation supplements server authorization; it never replaces it.
4. Use `FastMCPApp` or an app-enabled tool when the workflow needs an embedded form, choice, file upload, dashboard, table, or generative UI. Keep private app tools hidden from the model unless they independently belong in the model-facing catalog.
5. Keep credentials out of ordinary elicitation payloads when an OAuth or out-of-band authorization flow is appropriate.
6. Run `bin/mcp-elicitations PATH` to identify interaction code, then test accept, decline, cancel, invalid input, unsupported-client behavior, authorization failure, and replay/idempotency.

Use [agents/interaction-reviewer.md](agents/interaction-reviewer.md) to review trust boundaries and fallback behavior.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [batteryshark](https://github.com/batteryshark)
- **Source:** [batteryshark/skill-tap](https://github.com/batteryshark/skill-tap)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-batteryshark-skill-tap-mcp-elicitations
- Seller: https://agentstack.voostack.com/s/batteryshark
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
