Official agent skill

HTTP MCP Headers

by github in github/gh-aw

Implement secret-safe HTTP headers for MCP transport in gh-aw.

OfficialMITAuto-check passedTesting & QA

Install HTTP MCP Headers

skills CLI
$ npx skills add github/gh-aw --skill http-mcp-headers -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/gh-aw http-mcp-headers --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/http-mcp-headers .claude/skills/http-mcp-headers && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
http-mcp-headers
GitHub stars
5.3k
Token cost
~1.2k tokens
SKILL.md length
384 words
Files
1
Skills in repo
52
Repo updated
First seen
Licence
MIT

At a glance

Implement secret-safe HTTP headers for MCP transport in gh-aw.

  • Works in 2 steps: MCP Config (mcp-config.json) → Execution Step Environment Variables
  • Tasks that involve MCP servers
  • SKILL.md covers Problem Statement, Example Workflow, Generated Output and Implementation Details, plus 2 more sections
  • Reaches mcp.datadoghq.com; needs DD_API_KEY and DD_APPLICATION_KEY

What it does

HTTP MCP Headers is an agent skill from github/gh-aw, published by the product's own GitHub organization. Implement secret-safe HTTP headers for MCP transport in gh-aw.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering MCP servers and Integration testing. It works with Model Context Protocol. The repository describes itself as: GitHub Agentic Workflows. The licence is MIT.

When your agent uses it

  • Tasks that involve MCP servers
  • Tasks that involve Integration testing

Example prompts

  • “/http-mcp-headers”

Requirements

  • A credential in DD_API_KEY
  • A credential in DD_APPLICATION_KEY

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. MCP Config (mcp-config.json)
  2. Execution Step Environment Variables

What it can do on your machine

Read from SKILL.md and the folder at commit eb63040. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown, json and yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • mcp.datadoghq.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DD_API_KEY
    • DD_APPLICATION_KEY
    • COPILOT_GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

HTTP MCP Headers loads about 1.2k tokens when it runs. Until then it costs about 20 tokens; SKILL.md has 384 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~20
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/gh-aw at commit eb63040, republished under its MIT licence (© github). 384 words, ~1,209 tokens.

Download SKILL.mdSave it as .claude/skills/http-mcp-headers/SKILL.md (or your agent's skills folder).
name
http-mcp-headers
description
Implement secret-safe HTTP headers for MCP transport in gh-aw.

HTTP MCP Header Secret Support - Implementation Summary

Use this reference for HTTP MCP header secret support in the copilot engine.

Problem Statement

When HTTP MCP headers include GitHub Actions secrets, mcp-config.json must:

  1. Extract secrets from headers (e.g., ${{ secrets.DD_API_KEY }})
  2. Declare those env variables in the execution step
  3. Configure the MCP config's "env" section to passthrough those variables
  4. Use the passed variables in the headers section

Example Workflow

markdown
on:
  workflow_dispatch:
permissions:
  contents: read
engine: copilot
mcp-servers:
  datadog:
    type: http
    url: "https://mcp.datadoghq.com/api/unstable/mcp-server/mcp"
    headers:
      DD_API_KEY: "${{ secrets.DD_API_KEY }}"
      DD_APPLICATION_KEY: "${{ secrets.DD_APPLICATION_KEY }}"
      DD_SITE: "${{ secrets.DD_SITE || 'datadoghq.com' }}"
    allowed:
      - search_datadog_dashboards
      - search_datadog_slos
      - search_datadog_metrics
      - get_datadog_metric

# Datadog Dashboard Search

Search for Datadog dashboards and provide a summary.

Generated Output

1. MCP Config (mcp-config.json)
json
{
  "mcpServers": {
    "datadog": {
      "type": "http",
      "url": "https://mcp.datadoghq.com/api/unstable/mcp-server/mcp",
      "headers": {
        "DD_API_KEY": "${DD_API_KEY}",
        "DD_APPLICATION_KEY": "${DD_APPLICATION_KEY}",
        "DD_SITE": "${DD_SITE}"
      },
      "tools": [
        "search_datadog_dashboards",
        "search_datadog_slos",
        "search_datadog_metrics",
        "get_datadog_metric"
      ],
      "env": {
        "DD_API_KEY": "\\${DD_API_KEY}",
        "DD_APPLICATION_KEY": "\\${DD_APPLICATION_KEY}",
        "DD_SITE": "\\${DD_SITE}"
      }
    }
  }
}
2. Execution Step Environment Variables
yaml
env:
  DD_API_KEY: ${{ secrets.DD_API_KEY }}
  DD_APPLICATION_KEY: ${{ secrets.DD_APPLICATION_KEY }}
  DD_SITE: ${{ secrets.DD_SITE || 'datadoghq.com' }}
  COPILOT_GITHUB_TOKEN: ${{ secrets.COPILOT_GITHUB_TOKEN }}
  # ... other env vars

GH_AW_MCP_CONFIG is intentionally NOT in the YAML env: block — it is exported from the run script (export GH_AW_MCP_CONFIG="$HOME/.copilot/mcp-config.json") so $HOME is resolved at runtime. GitHub Actions does not shell-expand env: values, so the path must be set via export to work on self-hosted/containerized runners where HOME is not /home/runner.

Implementation Details

Key Functions
  1. extractSecretsFromValue(value string) - Extracts secret expressions from a string

    • Parses ${{ secrets.VAR_NAME }} patterns
    • Handles default values: ${{ secrets.VAR || 'default' }}
    • Returns map of variable names to full expressions
  2. extractSecretsFromHeaders(headers map[string]string) - Extracts all secrets from HTTP headers

    • Iterates through all header values
    • Collects all unique secret expressions
    • Returns consolidated map of secrets
  3. replaceSecretsWithEnvVars(value string, secrets map[string]string) - Replaces secret expressions with env var references

    • Transforms ${{ secrets.DD_API_KEY }} to ${DD_API_KEY}
    • Used in MCP config headers rendering
  4. collectHTTPMCPHeaderSecrets(tools map[string]any) - Collects secrets from all HTTP MCP tools

    • Scans all tools for HTTP MCP configurations
    • Extracts secrets from each tool's headers
    • Returns consolidated map for execution step env
Show full SKILL.md (149 more words)Show less
Rendering Logic
In renderSharedMCPConfig (mcp-config.go):
  1. Extract secrets when rendering HTTP MCP configs for copilot engine
  2. Add env section to property order when secrets are found
  3. Render headers with env var references instead of secret expressions
  4. Render env with passthrough syntax (\${VAR_NAME})
In GetExecutionSteps (copilot_engine.go):
  1. Collect all HTTP MCP header secrets from workflow tools
  2. Add to execution step env map with secret expressions

Security Benefits

  1. Secrets never appear in MCP config - Only env var references
  2. Proper GitHub Actions secret handling - Uses ${{ secrets.* }} syntax
  3. Environment isolation - Each MCP server receives only its required secrets
  4. Consistent pattern - Matches existing GitHub remote MCP server implementation

Test Coverage

Unit Tests (mcp_http_headers_test.go)
  • extractSecretsFromValue
  • extractSecretsFromHeaders
  • replaceSecretsWithEnvVars
  • collectHTTPMCPHeaderSecrets
  • renderSharedMCPConfig with HTTP headers
Integration Tests (copilot_mcp_http_integration_test.go)
  • Single HTTP MCP tool with secrets
  • Multiple HTTP MCP tools
  • HTTP MCP without secrets
  • Property ordering
  • Env variable sorting

All tests pass ✓

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/http-mcp-headers of github/gh-aw.

Open the folder on GitHubat commit eb63040

Compare with similar skills

HTTP MCP Headers next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

HTTP MCP Headers compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
HTTP MCP Headers this skillgithub/gh-aw5.3k—~1.2kAutomated safety check: PassMIT
MCP Testingadeze/raindrop-mcp188—~1.6kAutomated safety check: PassMIT
remindb Integration Testsradimsem/remindb129—~1.8kAutomated safety check: PassMIT
Sapui5secondsky/sap-skills460—~4.1kAutomated safety check: PassGPL-3.0
Qwen Code E2E TestingQwenLM/qwen-code28k—~2.1kAutomated safety check: PassApache-2.0
Adding LLM MCP ToolsTriliumNext/Trilium38k—~2.5kAutomated safety check: PassAGPL-3.0

Similar skills

  • MCP Testing

    adeze/raindrop-mcp

    MCP Testing Strategies with Vitest, Inspector, and Integration Tests

    188 GitHub stars~1.6k tokensUpdated 2 mo ago
    Testing & QAAuto-check passed
  • Explains how to add an end-to-end test scenario to remindb, choosing between a direct API test and an MCP test and using the shared helpers and fixtures.

    129 GitHub stars~1.8k tokensUpdated 2 mo ago
    Testing & QAAuto-check passed
  • Sapui5

    secondsky/sap-skills

    This skill should be used when developing SAP UI5 applications, including creating freestyle apps, Fiori Elements apps, custom controls, testing, data binding, OData integration, routing, and…

    460 GitHub stars~4.1k tokensUpdated 2 days ago
    Testing & QAAuto-check passed
  • Qwen Code E2E Testing

    QwenLM/qwen-code

    Guides end-to-end testing of the Qwen Code CLI in headless mode with real model calls, MCP test servers and inspection of raw API traffic.

    28k GitHub stars~2.1k tokensUpdated today
    Testing & QAAuto-check passed
  • Adding LLM MCP Tools

    TriliumNext/Trilium

    A skill your agent uses when adding, changing, or reviewing an LLM/MCP tool in Trilium (the defineTools definitions under packages/trilium-core/src/services/llm/tools/ —…

    38k GitHub stars~2.5k tokensUpdated today
    Testing & QAAuto-check passed
  • Agentacct Workflow

    mikehasa/agentacct

    A skill your agent uses when working in a repo with agentacct MCP configured, or when asked to track coding-agent work, smoke-test agentacct integrations, or report objective AI-agent task evidence.

    765 GitHub stars~1.6k tokensUpdated 4 days ago
    Testing & QAAuto-check passed

More from github/gh-aw

All 52 skills in this repo
  • Official

    Drives a real browser from the command line with playwright-cli to open pages, interact, mock requests, save state and work with Playwright tests.

    5.3k GitHub starsUsed in 23 repos~2.8k tokens
    Auto-check passed
  • Official

    Designs and verifies a deterministic grader that measures whether a GitHub Agentic Workflow run reached its real-world or repository outcome.

    5.3k GitHub stars~6.8k tokensUpdated today
    Auto-check passed
  • Official

    Scaffolds, edits, reloads and debugs a canvas extension that the GitHub Copilot CLI can open in its side panel.

    5.3k GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Official

    Drives an open pull request to merge-ready from inside a GitHub Copilot cloud agent, resolving review threads and local checks concurrently, without merging or retriggering CI.

    5.3k GitHub stars~3.8k tokensUpdated today
    Auto-check: warnings
  • Official

    Bumps gh-aw's pinned gh-aw-firewall version, rebuilds generated artifacts, and flags upstream spec or schema changes that need follow-up work.

    5.3k GitHub stars~899 tokensUpdated today
    Auto-check passed
  • Official

    Guide to the console struct tag system in gh-aw: headers, titles, number and cost formats, omitempty, and how structs, slices and maps render in the terminal.

    5.3k GitHub stars~736 tokensUpdated today
    Auto-check passed

Categories

Questions about HTTP MCP Headers

What does HTTP MCP Headers do?

Implement secret-safe HTTP headers for MCP transport in gh-aw. HTTP MCP Headers is an agent skill from github/gh-aw, published by the product's own GitHub organization. Implement secret-safe HTTP headers for MCP transport in gh-aw.

When should I use HTTP MCP Headers?

HTTP MCP Headers fits situations like: tasks that involve MCP servers; tasks that involve Integration testing.

How do I install HTTP MCP Headers in Claude Code?

Run `npx skills add github/gh-aw --skill http-mcp-headers -a claude-code`. Or copy the skill folder (.github/skills/http-mcp-headers in github/gh-aw) into .claude/skills/http-mcp-headers in your project. Claude Code loads it when a task matches its description.

How do I install HTTP MCP Headers in Codex?

Run `npx skills add github/gh-aw --skill http-mcp-headers -a codex`. Or copy the skill folder (.github/skills/http-mcp-headers in github/gh-aw) into .agents/skills/http-mcp-headers in your project. Codex loads it when a task matches its description.

Can I use HTTP MCP Headers in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw --skill http-mcp-headers -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/http-mcp-headers, .gemini/skills/http-mcp-headers, .github/skills/http-mcp-headers and .opencode/skills/http-mcp-headers in your project.

What does HTTP MCP Headers need to run?

Going by SKILL.md and its folder, HTTP MCP Headers needs credentials named DD_API_KEY, DD_APPLICATION_KEY and COPILOT_GITHUB_TOKEN. Our summary lists: A credential in DD_API_KEY; A credential in DD_APPLICATION_KEY.

Does HTTP MCP Headers access the network?

SKILL.md names 1 domain. In commands or code: mcp.datadoghq.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is HTTP MCP Headers safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does HTTP MCP Headers use?

HTTP MCP Headers is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does HTTP MCP Headers use?

About 1.2k tokens (SKILL.md is roughly 4.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to HTTP MCP Headers?

Skills that share tags, products or a category with HTTP MCP Headers: MCP Testing (adeze/raindrop-mcp, 188 stars), remindb Integration Tests (radimsem/remindb, 129 stars), Sapui5 (secondsky/sap-skills, 460 stars) and Qwen Code E2E Testing (QwenLM/qwen-code, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains HTTP MCP Headers?

github (a GitHub organization, an official publisher) maintains it in github/gh-aw, which has 5,350 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on October 7, 2026.

Source: github/gh-aw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.