Debug issues in the MCP Gateway Registry using first-principles thinking.

Apache-2.0Auto-check: notesDevelopment

Install Debug

skills CLI
$ npx skills add agentic-community/mcp-gateway-registry --skill debug -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install agentic-community/mcp-gateway-registry debug --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/agentic-community/mcp-gateway-registry.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/debug .claude/skills/debug && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
debug
GitHub stars
962
Token cost
~1.8k tokens
SKILL.md length
1,009 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

Debug issues in the MCP Gateway Registry using first-principles thinking.

  • Works in 6 steps: Reproduce and observe (do NOT theorize… → Check what the worker is DOING right now → Is this new or pre-existing? → …
  • Tasks that involve Debugging
  • SKILL.md covers Expert Personas, First Principles Debugging, Anti-patterns to avoid and Debugging checklist (copy into…
  • Calls docker

What it does

Debug is an agent skill from agentic-community/mcp-gateway-registry. Debug issues in the MCP Gateway Registry using first-principles thinking. Invoke when something is broken, timing out, returning errors, or behaving unexpectedly. Forces structured root-cause analysis before any code change is proposed.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Debugging, Root cause analysis and MCP servers. It works with Model Context Protocol. The repository describes itself as: Enterprise-ready MCP Gateway & Registry that centralizes AI development tools with secure OAuth authentication, dynamic tool discovery, and unified access for both autonomous AI… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Debugging
  • Tasks that involve Root cause analysis
  • Tasks that involve MCP servers

Example prompts

  • “/debug”

Requirements

  • Python 3
  • Docker

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Reproduce and observe (do NOT theorize yet)
  2. Check what the worker is DOING right now
  3. Is this new or pre-existing?
  4. If you see something suspicious in the logs, ask HOW it connects
  5. Before proposing a code change, answer these questions
  6. Cross-question your own theory

What it can do on your machine

Read from SKILL.md and the folder at commit ec3a197. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Debug loads about 1.8k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 1,009 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:71
    ?** Could this be a configuration issue (.env, timeout, feature flag)?

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from agentic-community/mcp-gateway-registry at commit ec3a197, republished under its Apache-2.0 licence (© agentic-community). 1,009 words, ~1,826 tokens.

Download SKILL.mdSave it as .claude/skills/debug/SKILL.md (or your agent's skills folder).
name
debug
description
Debug issues in the MCP Gateway Registry using first-principles thinking. Invoke when something is broken, timing out, returning errors, or behaving unexpectedly. Forces structured root-cause analysis before any code change is proposed.
license
Apache-2.0
metadata.author
mcp-gateway-registry
metadata.version
1.0

Debug Skill

Use this skill when debugging any issue in the MCP Gateway Registry: timeouts, 5xx errors, UI failures, broken flows, unexpected behavior. Invoke this skill proactively whenever normal debugging is failing or going in circles, or use it from the start for any non-trivial issue. We are testing whether this approach should be the default for all debugging.

Expert Personas

Before starting, announce that you are consulting the following expert panel. Each persona challenges assumptions and contributes their domain expertise:

  • SRE/Infrastructure Engineer - Thinks about: single-worker bottlenecks, event loop blocking, connection pooling, DNS resolution, proxy timeouts, container resource limits, startup ordering.
  • Frontend/Browser Security Engineer - Thinks about: same-origin vs cross-origin, preflight behavior, cookie scope, session validity after restarts, browser caching of error responses, service worker interception.
  • Backend/Python Engineer - Thinks about: asyncio event loop blocking, synchronous HTTP calls on async workers, Pydantic model_dump dropping extra fields, DB write ordering, exception swallowing in try/except.
  • Senior Staff Engineer (Skeptic) - Questions EVERY theory before implementation. Asks: "If that were true, why does X work?" and "Was this working before our change?" Forces the team to prove hypotheses before writing code.

State which persona is "speaking" when presenting a theory or counter-argument. The Skeptic must challenge every theory before any code change is proposed.

First Principles Debugging

Step 1: Reproduce and observe (do NOT theorize yet)
  • What exact error does the user see? (HTTP status, error message, timing)
  • What was the user doing? (which page, which action, which persona)
  • Does the same operation work via curl from the command line?
  • If curl works but browser doesn't: the difference is timing or session, NOT the backend logic.
Step 2: Check what the worker is DOING right now

This is the single most important step. The registry runs a single uvicorn worker. If a request times out, the worker is busy doing something else.

bash
docker compose logs registry --since=30s 2>&1 | tail -30

Read what the logs say at the EXACT timestamp of the failure. Do NOT filter by keywords related to your bug. Look at EVERYTHING the worker is doing. Common blockers:

  • GoDaddy ANS API pagination (hundreds of sequential HTTP GETs)
  • Federation sync (AgentCore, peer registries)
  • Health checks pinging 30+ MCP servers
  • Vector index processing (embedding generation, index updates)
  • Security scans (yara, spec analyzers take 3-8 seconds each)

If the worker is busy with a background task, your request is queued. The fix is to make that task non-blocking, NOT to change the endpoint code.

Step 3: Is this new or pre-existing?

Before touching ANY code, answer:

  • Was this working before on the current branch?
  • Was this working on main / the last release tag?
  • Did a recent restart, rebuild, or config change cause it?

If the issue exists on the baseline tag with zero changes, it is pre-existing and unrelated to whatever PR you are working on. Do NOT fix pre-existing issues in a PR scoped to something else unless the user explicitly asks.

Step 4: If you see something suspicious in the logs, ask HOW it connects

When you see an error or warning in the logs, do NOT immediately assume it is the root cause. Ask:

  • Is this error on the code path of the failing request, or is it a different background operation?
  • Does this error BLOCK the worker, or is it caught and handled?
  • Would fixing this error actually change the user-visible symptom?

Example: seeing FAISS index not initialized in logs does NOT mean FAISS is the problem. It might be a non-fatal warning from a background task that runs in parallel. Trace the actual call stack of the failing request.

Show full SKILL.md (420 more words)Show less
Step 5: Before proposing a code change, answer these questions
  1. Is a code change actually needed? Could this be a configuration issue (.env, timeout, feature flag)?
  2. Present options to the user before implementing. Do NOT just pick a fix and implement it. Present 2-3 well-thought-out options with trade-offs (complexity, risk, scope, reversibility) and let the user choose. One-line fixes are preferred over architectural changes, but the user decides.
  3. Does this fix have side effects? Does it change behavior for OTHER callers, OTHER deployments, OTHER code paths?
  4. Will hot-patching work? If you docker-cp a file into a running container:
    • The restart will invalidate sessions (auth-server restart = all browser cookies invalid)
    • nginx_service.py will re-render the nginx config on startup (may break routing)
    • Startup tasks will re-run (may block the worker for 30+ seconds)
    • Consider whether a simple rebuild is faster than iterative hot-patching.
  5. Does this need a test? If you are changing backend logic, YES. Always.
Step 6: Cross-question your own theory

Before implementing, argue against your own hypothesis:

  • "If CORS is the problem, why do all the GETs work from the same browser?"
  • "If the scan timeout is the problem, why does curl finish in 5 seconds?"
  • "If nginx is blocking the request, why is there no error in the nginx error log?"
  • "If the session is invalid, why did the dashboard load successfully moments ago?"

If you cannot answer the counter-question, your theory is wrong. Go back to Step 2.

Anti-patterns to avoid

  • Do NOT chase CORS on same-origin requests. If the browser URL and the API URL have the same scheme + host + port, CORS does not apply. Period.
  • Do NOT hot-patch containers repeatedly. Each restart creates new state. After 2 failed hot-patches, do a clean build_and_run.sh and test once.
  • Do NOT make async/background changes to "fix" a timeout unless you have proven the timeout is caused by the specific function you are making async. The real cause is usually a DIFFERENT function blocking the worker.
  • Do NOT add CORS, nginx, or auth-server changes without first confirming the request actually reaches (or fails to reach) those layers. Check logs at each layer in order: nginx access log → auth-server validate → registry endpoint.
  • Do NOT assume "no logs = request didn't reach the backend." It might mean the worker is busy processing something else and your request is queued behind it.

Debugging checklist (copy into your response)

When debugging, paste this and fill it in:

[ ] Exact error: ___
[ ] Same operation via curl: works / fails / different error
[ ] Registry logs at failure timestamp show: ___
[ ] Worker was busy doing: ___ (or idle)
[ ] Pre-existing on baseline? yes / no / untested
[ ] Theory: ___
[ ] Counter-argument against theory: ___
[ ] Theory survives counter-argument? yes / no

Only propose a fix after all boxes are checked and the theory survives.

© agentic-community, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/debug of agentic-community/mcp-gateway-registry.

Open the folder on GitHubat commit ec3a197

Compare with similar skills

Debug next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Debug compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Debug this skillagentic-community/mcp-gateway-registry962—~1.8kAutomated safety check: NotesApache-2.0
Flowstudio Power Automate Debuggithub/awesome-copilot40k2 repos~5kAutomated safety check: PassMIT
Flowstudio Power Automate Monitoringgithub/awesome-copilot40k2 repos~3.3kAutomated safety check: PassMIT
QA Find Bugs MCPbex-co/beancount-io294—~3kAutomated safety check: PassMIT
QA Find Bugs Mobilebex-co/beancount-io294—~2.2kAutomated safety check: NotesMIT
LangBot Plugin Developmentlangbot-app/LangBot18k—~3.9kAutomated safety check: PassApache-2.0

Similar skills

  • Flowstudio Power Automate Debug

    github/awesome-copilot

    Official

    Debug failing Power Automate cloud flows using the FlowStudio MCP server.

    40k GitHub starsUsed in 2 repos~5k tokens
    DevelopmentAuto-check passed
  • Official

    Pro+ subscription required. An agent skill from github/awesome-copilot.

    40k GitHub starsUsed in 2 repos~3.3k tokens
    DevelopmentAuto-check passed
  • QA Find Bugs MCP

    bex-co/beancount-io

    Hunt bugs in the Beancount.io remote MCP server by driving the real POST /api-gateway/mcp endpoint with JSON-RPC and real MCP clients, checking transport, discovery, credential boundaries, tool and…

    294 GitHub stars~3k tokensUpdated today
    Backend & APIsAuto-check passed
  • QA Find Bugs Mobile

    bex-co/beancount-io

    Hunt bugs in the running Beancount mobile app using local Expo MCP on the iPhone 17e simulator, sign in with QAEMAIL and QAPASSWORD, reproduce failures, trace root causes, and deduplicate findings.

    294 GitHub stars~2.2k tokensUpdated today
    MobileAuto-check: notes
  • LangBot Plugin Development

    langbot-app/LangBot

    Guides building, debugging and testing LangBot plugins: components, SDK calls, README and locale rules, SDK pitfalls and WebSocket-based testing.

    18k GitHub stars~3.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Graph-Based Bug Tracing

    tirth8205/code-review-graph

    Traces a bug through a code knowledge graph, following callers, callees and execution flow before opening source files, within a small token budget.

    32k GitHub starsUsed in 1 repo~287 tokens
    DevelopmentAuto-check passed

More from agentic-community/mcp-gateway-registry

All 17 skills in this repo
  • Explainer

    agentic-community/mcp-gateway-registry

    Explain a GitHub issue or pull request at 100, 200, and 300 level.

    962 GitHub stars~3.8k tokensUpdated yesterday
    Auto-check passed
  • Infra Sync

    agentic-community/mcp-gateway-registry

    Keep Terraform and CDK infrastructure in sync. An agent skill from agentic-community/mcp-gateway-registry.

    962 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Search Benchmark

    agentic-community/mcp-gateway-registry

    Generate a search quality benchmark for the AI Registry. An agent skill from agentic-community/mcp-gateway-registry.

    962 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Writing

    agentic-community/mcp-gateway-registry

    Write prose people will actually read. An agent skill from agentic-community/mcp-gateway-registry.

    962 GitHub stars~3.5k tokensUpdated yesterday
    Auto-check passed
  • Agentcore Register

    agentic-community/mcp-gateway-registry

    Given an MCP server URL, probe the server via curl to discover its metadata and tools, then generate a markdown file with copy-pasteable content for each field in the Amazon Bedrock AgentCore…

    962 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Benchmark Report

    agentic-community/mcp-gateway-registry

    Generate a benchmark report from stress test results (registration, API performance, search concurrency).

    962 GitHub stars~590 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Debug

What does Debug do?

Debug issues in the MCP Gateway Registry using first-principles thinking. Debug is an agent skill from agentic-community/mcp-gateway-registry. Debug issues in the MCP Gateway Registry using first-principles thinking.

When should I use Debug?

Debug fits situations like: tasks that involve Debugging; tasks that involve Root cause analysis; tasks that involve MCP servers.

How do I install Debug in Claude Code?

Run `npx skills add agentic-community/mcp-gateway-registry --skill debug -a claude-code`. Or copy the skill folder (.claude/skills/debug in agentic-community/mcp-gateway-registry) into .claude/skills/debug in your project. Claude Code loads it when a task matches its description.

How do I install Debug in Codex?

Run `npx skills add agentic-community/mcp-gateway-registry --skill debug -a codex`. Or copy the skill folder (.claude/skills/debug in agentic-community/mcp-gateway-registry) into .agents/skills/debug in your project. Codex loads it when a task matches its description.

Can I use Debug in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agentic-community/mcp-gateway-registry --skill debug -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/debug, .gemini/skills/debug, .github/skills/debug and .opencode/skills/debug in your project.

What does Debug need to run?

Going by SKILL.md and its folder, Debug needs the command-line tools its instructions call (docker). Our summary lists: Python 3; Docker.

Does Debug access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Debug safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Debug use?

Debug is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Debug use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Debug?

Skills that share tags, products or a category with Debug: Flowstudio Power Automate Debug (github/awesome-copilot, 40k stars), Flowstudio Power Automate Monitoring (github/awesome-copilot, 40k stars), QA Find Bugs MCP (bex-co/beancount-io, 294 stars) and QA Find Bugs Mobile (bex-co/beancount-io, 294 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Debug?

agentic-community (a GitHub organization) maintains it in agentic-community/mcp-gateway-registry, which has 962 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 6, 2026.

Source: agentic-community/mcp-gateway-registry on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.