skillset.
Sell a skill

For creators

Why hosted instructions are not DRM

Explain the value of maintained MCP delivery without promising that delivered text cannot be copied.

Skillset · 3 min read · Updated

Quick answer

MCP delivery can check access before supplying a skill and provide a current approved source. It cannot make instructions unreadable to the AI receiving them or guarantee that a person will never copy the output. Sell a useful, maintained workflow with honest access terms, rather than promising technical control over every delivered copy.

Follow the instructions to their destination

When a buyer asks a compatible AI app to use a Skillset skill, the app requests the workflow and receives its instructions. MCP defines context exchange between a host and server; it does not dictate everything the host does with that context. Hosted retrieval therefore differs from keeping the method entirely on a server.

Source: MCP architecture overview

Separate future access from past delivery

Imagine a fictional outreach-planning skill loaded into a conversation on Monday. If the account’s access is later revoked, Skillset can deny another request when no other valid entitlement remains. It cannot promise to remove Monday’s text from that conversation, an export, or a copy the buyer already made.

Disconnecting an AI app and canceling a subscription are also separate actions. One concerns the connection’s authorization; the other concerns a billing agreement. Do not suggest that either action automatically erases previously delivered instructions. Explain this limit before using copying prevention as a reason to buy.

Build the offer around value you actually maintain

A maintained source can offer reviewed releases, clearer examples, fixes to confusing decisions, and an easier way to retrieve the right workflow. For the outreach example, ongoing work might improve how the skill checks evidence before drafting a message or how it handles an unavailable contact channel.

Show those improvements through a release example: the old method assumed a channel, while the revised method asks which channel is authorized. That is a concrete reason to prefer the maintained version. It does not require a claim that screenshots, copied instructions, or conversation exports are impossible.

Keep secrets and permissions outside the content

Do not put your account key, another customer’s records, or a private credential into a skill and rely on MCP to hide it. Supply fictional examples and describe required connections. If a workflow fundamentally needs secret server-side computation, instruction delivery alone is not that implementation.

Keep promotional wording specific: “Load the approved workflow through your Skillset connection” describes the product. “Nobody can view or share the skill” promises a protection this architecture does not provide. License terms and permitted uses should be stated in the relevant offer; they should not be presented as an automatic technical barrier.

Common questions

Can buyers inspect the skill instructions?

Skillset provides a protected view for eligible owned skills, and an AI must receive instructions to apply them. Do not promise that the text is invisible to authorized users.

Does this mean hosted delivery has no access control?

No. The server checks authorization for new retrievals. The limit is control over instructions already delivered, not whether the server can deny a future request.

Should I include a secret so only my workflow works?

No. Secrets belong in an appropriate credential or service mechanism, never in delivered instruction text. A hidden-looking token is still a token someone may receive.

Put a workflow to work.

Connect your library to your AI, or turn your method into a skill.