The GitHub Copilot app now ships with a Customize tab, a single pane that lists MCP servers, plugins, skills, and canvases. By surfacing these extensions together, the app gives engineers a faster path to discover and enable the pieces that shape Copilot’s behavior in their existing toolchains.
What changed: the Copilot customization hub
The new tab groups four categories—MCP servers, plugins, skills, and canvases—under a unified UI. It highlights a set of “featured” items drawn from each category, offers a trending view for MCP servers, and lets users browse by type or category. The entry point is simply opening the Copilot app and selecting Customize.
Why it matters to AI, cloud, DevOps, and security engineers
All four practitioner groups rely on extensions that tailor AI assistance to their pipelines. The hub reduces the friction of locating the right plugin or skill, which can accelerate adoption in CI/CD, infrastructure‑as‑code, or security‑automation workflows. For teams using Azure DevOps, the hub explicitly mentions the ability to delegate triage, backlog prioritisation, and follow‑up tasks to Copilot, directly tying AI assistance to issue‑tracking processes.
Operational and security considerations
Bringing extensions into a single view introduces a few practical questions:
- Discovery vs. governance: While the featured view simplifies onboarding, teams should still vet each MCP server, plugin, skill, or canvas before activation to ensure it aligns with internal policies.
- Configuration overhead: Each customisation may require its own settings (e.g., endpoint URLs for MCP servers). Operators need to track these configurations alongside existing infrastructure code.
- Dependency management: Plugins and skills could pull in additional runtime dependencies. Maintaining version compatibility with the Copilot runtime becomes part of the release process.
- Security posture: Because the hub can surface third‑party canvases and plugins, security engineers should assess the provenance and potential attack surface of any new component before it is granted execution rights.
Related CloudNinjas coverage: AI engineering.
What This Means For Practitioners
Adopt the following short checklist when evaluating the new hub:
- Review the featured customisations and map them to existing workflow gaps.
- Run a lightweight security review on any third‑party plugin, skill, or canvas you plan to enable.
- Document configuration changes in your infrastructure‑as‑code repository to keep the Copilot extension set version‑controlled.
- Pilot the Azure DevOps delegation flow on a non‑critical backlog to measure impact on throughput and review quality.
By treating the Customize tab as a controlled entry point rather than an unchecked marketplace, teams can reap the productivity benefits while keeping operational and security risks in check.


