SaaS Connector & Autonomous MCP Architecture Skill
This skill guides AI agents in implementing and extending the enterprise SaaS capabilities of the GitHub Backup Automation System, including UI connectors, encrypted secret vaults, multi-cloud storage backends, and Model Context Protocol (MCP) server integrations.
1. UI Connector Hub & Encrypted Credential Vault
When implementing or modifying connectors:
- Zero
.env for Users: User-provided API keys and connections MUST be stored in the connectors database table with AES-256-GCM envelope encryption.
- OpenRouter Pool: Support multiple OpenRouter API keys with in-memory round-robin rotation, latency tracking, and automatic failover.
- Database Connectors: Provide connection validation and branch selection for Neon, Supabase, and self-hosted PostgreSQL.
- Health Checks: Connectors must implement a periodic health check loop (
last_health_check, health_status).
2. Pluggable Multi-Cloud Storage Engine
When extending backup archiving and storage destinations:
- All storage drivers must implement the Go
StorageProvider interface:type StorageProvider interface {
Upload(ctx context.Context, key string, r io.Reader, size int64) error
Download(ctx context.Context, key string, w io.Writer) error
VerifyChecksum(ctx context.Context, key string, expectedSHA256 string) (bool, error)
Delete(ctx context.Context, key string) error
List(ctx context.Context, prefix string) ([]ObjectMetadata, error)
}
- Providers to support: AWS S3, Cloudflare R2, MinIO, Google Drive (OAuth), Azure Blob, Local Filesystem.
- Streaming uploads should stream directly from memory / pipe to the cloud without requiring massive local disk scratch space.
3. Model Context Protocol (MCP) Server Integration
When adding new MCP tools to the LangChain / FastAPI agent:
- Protocol Adherence: Connect via standard MCP JSON-RPC protocol over Stdio or SSE.
- Human-In-The-Loop (HITL) Enforcement:
- Read-only tools (
query_database_state, list_backups, inspect_container) execute automatically.
- Destructive or external actions (
restart_service, restore_database_snapshot, trigger_incident_alert, apply_schema_migration) MUST trigger the HITL confirmation protocol via SSE event.
- Structured Response Synthesis:
- All MCP tool outputs must be synthesized concisely in structured Markdown without emojis or conversational filler.
4. Exposing the Native GitHub Backup MCP Server (github-backup-mcp)
When maintaining or extending the native MCP server exposed to external IDEs/agents:
- Implement tools under
github-backup-mcp:
get_system_health: Real-time status of services, DB, and latest runs.
trigger_backup_run: Autonomous run triggers for specified repos.
search_observatory_knowledge: Hybrid pgvector search across system logs.
verify_archive_integrity: SHA-256 validation of .tar.gz archives.
extract_backup_file: Surgical extraction from remote S3/R2 backups.
- Expose over both standard stdio transport and HTTP/SSE transport for web-based agents.
1---2name: saas-and-mcp-architecture3description: Architectural patterns and implementation guidelines for the SaaS Connector Hub, pluggable multi-cloud storage engines, and Model Context Protocol (MCP) tool expansion.4---56# SaaS Connector & Autonomous MCP Architecture Skill78This skill guides AI agents in implementing and extending the enterprise SaaS capabilities of the **GitHub Backup Automation System**, including UI connectors, encrypted secret vaults, multi-cloud storage backends, and Model Context Protocol (MCP) server integrations.910---1112## 1. UI Connector Hub & Encrypted Credential Vault1314When implementing or modifying connectors:1516* **Zero `.env` for Users**: User-provided API keys and connections MUST be stored in the `connectors` database table with AES-256-GCM envelope encryption.17* **OpenRouter Pool**: Support multiple OpenRouter API keys with in-memory round-robin rotation, latency tracking, and automatic failover.18* **Database Connectors**: Provide connection validation and branch selection for Neon, Supabase, and self-hosted PostgreSQL.19* **Health Checks**: Connectors must implement a periodic health check loop (`last_health_check`, `health_status`).2021---2223## 2. Pluggable Multi-Cloud Storage Engine2425When extending backup archiving and storage destinations:2627* All storage drivers must implement the Go `StorageProvider` interface:28 ```go29 type StorageProvider interface {30 Upload(ctx context.Context, key string, r io.Reader, size int64) error31 Download(ctx context.Context, key string, w io.Writer) error32 VerifyChecksum(ctx context.Context, key string, expectedSHA256 string) (bool, error)33 Delete(ctx context.Context, key string) error34 List(ctx context.Context, prefix string) ([]ObjectMetadata, error)35 }36 ```37* Providers to support: AWS S3, Cloudflare R2, MinIO, Google Drive (OAuth), Azure Blob, Local Filesystem.38* Streaming uploads should stream directly from memory / pipe to the cloud without requiring massive local disk scratch space.3940---4142## 3. Model Context Protocol (MCP) Server Integration4344When adding new MCP tools to the LangChain / FastAPI agent:45461. **Protocol Adherence**: Connect via standard MCP JSON-RPC protocol over Stdio or SSE.472. **Human-In-The-Loop (HITL) Enforcement**:48 - Read-only tools (`query_database_state`, `list_backups`, `inspect_container`) execute automatically.49 - Destructive or external actions (`restart_service`, `restore_database_snapshot`, `trigger_incident_alert`, `apply_schema_migration`) MUST trigger the HITL confirmation protocol via SSE event.503. **Structured Response Synthesis**:51 - All MCP tool outputs must be synthesized concisely in structured Markdown without emojis or conversational filler.5253---5455## 4. Exposing the Native GitHub Backup MCP Server (`github-backup-mcp`)5657When maintaining or extending the native MCP server exposed to external IDEs/agents:5859* Implement tools under `github-backup-mcp`:60 - `get_system_health`: Real-time status of services, DB, and latest runs.61 - `trigger_backup_run`: Autonomous run triggers for specified repos.62 - `search_observatory_knowledge`: Hybrid pgvector search across system logs.63 - `verify_archive_integrity`: SHA-256 validation of `.tar.gz` archives.64 - `extract_backup_file`: Surgical extraction from remote S3/R2 backups.65* Expose over both standard stdio transport and HTTP/SSE transport for web-based agents.66