Agent skill

MCP Gateway Configuration

by Hack23 in Hack23/cia

MCP gateway setup for multi-server integration, security configuration, tool routing, and access control

Apache-2.0Auto-check passedAgent Workflows

Install MCP Gateway Configuration

skills CLI
$ npx skills add Hack23/cia --skill mcp-gateway-configuration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia mcp-gateway-configuration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/mcp-gateway-configuration .claude/skills/mcp-gateway-configuration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mcp-gateway-configuration
GitHub stars
239
Token cost
~1.8k tokens
SKILL.md length
413 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

MCP gateway setup for multi-server integration, security configuration, tool routing, and access control

  • Works in 4 steps: Least Privilege — Each server should… → Separation of Concerns — Different… → Fail-Safe Defaults — Tools should… → …
  • Tasks that involve MCP servers
  • SKILL.md covers Purpose, When to Use This Skill, MCP Architecture Overview and Configuration Structure, plus 7 more sections
  • Calls python3 and npx; needs GITHUB_TOKEN and MCP_TOKEN

What it does

MCP Gateway Configuration is an agent skill from Hack23/cia. MCP gateway setup for multi-server integration, security configuration, tool routing, and access control

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering MCP servers and Authorization and RBAC. It works with Model Context Protocol and GitHub. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve MCP servers
  • Tasks that involve Authorization and RBAC

Example prompts

  • “/mcp-gateway-configuration”

Requirements

  • Python 3
  • Node.js
  • A credential in MCP_TOKEN
  • A credential in GITHUB_TOKEN

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Least Privilege — Each server should only expose tools needed for its purpose
  2. Separation of Concerns — Different servers for different capabilities
  3. Fail-Safe Defaults — Tools should default to read-only when possible
  4. Audit Trail — All tool invocations should be logged

What it can do on your machine

Read from SKILL.md and the folder at commit bbed538. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • modelcontextprotocol.io
    • docs.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN
    • MCP_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

MCP Gateway Configuration loads about 1.8k tokens when it runs. Until then it costs about 33 tokens; SKILL.md has 413 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~33
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit bbed538, republished under its Apache-2.0 licence (© Hack23). 413 words, ~1,833 tokens.

Download SKILL.mdSave it as .claude/skills/mcp-gateway-configuration/SKILL.md (or your agent's skills folder).
name
mcp-gateway-configuration
description
MCP gateway setup for multi-server integration, security configuration, tool routing, and access control
license
Apache-2.0

MCP Gateway Configuration Skill

Purpose

This skill provides guidance for configuring MCP (Model Context Protocol) gateways for the CIA platform. It covers multi-server integration, tool routing, security configuration, and access control to enable secure and efficient AI-assisted development workflows.

When to Use This Skill

Apply this skill when:

  • ✅ Setting up or modifying .github/copilot-mcp-config.json
  • ✅ Adding new MCP servers to the gateway
  • ✅ Configuring tool routing between MCP servers
  • ✅ Setting up access control for MCP tools
  • ✅ Troubleshooting MCP connectivity issues
  • ✅ Reviewing MCP configuration for security
  • ✅ Integrating new data sources via MCP

Do NOT use for:

  • ❌ MCP security hardening (use mcp-gateway-security)
  • ❌ General API gateway configuration (different pattern)
  • ❌ Application-level API design (use service layer patterns)

MCP Architecture Overview

┌─────────────────────────────────────────────┐
│              GitHub Copilot                  │
│          (AI Assistant Client)               │
└──────────────────┬──────────────────────────┘
                   │
                   ▼
┌─────────────────────────────────────────────┐
│           MCP Gateway Layer                  │
│  ┌─────────────────────────────────────┐    │
│  │   copilot-mcp-config.json           │    │
│  │   - Server definitions              │    │
│  │   - Tool routing rules              │    │
│  │   - Access control policies         │    │
│  └─────────────────────────────────────┘    │
└──────┬──────────┬──────────┬────────────────┘
       │          │          │
       ▼          ▼          ▼
┌──────────┐ ┌──────────┐ ┌──────────┐
│ GitHub   │ │ Filesystem│ │ Playwright│
│ MCP      │ │ MCP      │ │ MCP      │
│ Server   │ │ Server   │ │ Server   │
└──────────┘ └──────────┘ └──────────┘

Configuration Structure

Base Configuration (copilot-mcp-config.json)
json
{
  "mcpServers": {
    "server-name": {
      "type": "stdio",
      "command": "command-to-run",
      "args": ["arg1", "arg2"],
      "env": {
        "ENV_VAR": "value"
      }
    }
  }
}
Server Type Patterns

stdio Servers (Local Process):

json
{
  "filesystem": {
    "type": "stdio",
    "command": "npx",
    "args": ["-y", "@modelcontextprotocol/server-filesystem", "/path/to/allowed"],
    "env": {}
  }
}

SSE Servers (Remote HTTP):

json
{
  "remote-server": {
    "type": "sse",
    "url": "https://mcp-server.example.com/sse",
    "headers": {
      "Authorization": "Bearer ${MCP_TOKEN}"
    }
  }
}

CIA Platform MCP Servers

Required Servers
ServerPurposeTools Provided
githubRepository operationsIssues, PRs, code search, Actions
filesystemLocal file operationsRead, write, search files
playwrightBrowser automationUI testing, screenshots
Configuration Best Practices

1. Minimize Filesystem Access:

json
{
  "filesystem": {
    "type": "stdio",
    "command": "npx",
    "args": [
      "-y", "@modelcontextprotocol/server-filesystem",
      "/home/runner/work/cia/cia"
    ]
  }
}

Only expose the project root — never expose /, /home, or parent directories.

2. Use Environment Variables for Secrets:

json
{
  "github": {
    "type": "stdio",
    "command": "github-mcp-server",
    "env": {
      "GITHUB_TOKEN": "${GITHUB_TOKEN}"
    }
  }
}

Never hardcode tokens in configuration files.

3. Specify Exact Package Versions:

json
{
  "args": ["-y", "@modelcontextprotocol/server-filesystem@1.2.3"]
}

Pin versions to prevent supply chain attacks.

Tool Routing

Routing Principles
  1. Least Privilege — Each server should only expose tools needed for its purpose
  2. Separation of Concerns — Different servers for different capabilities
  3. Fail-Safe Defaults — Tools should default to read-only when possible
  4. Audit Trail — All tool invocations should be logged
Show full SKILL.md (165 more words)Show less
Tool Categories
CategoryServerExample Tools
Code Managementgithubcreate_pull_request, push_files
Code Analysisgithubsearch_code, get_file_contents
File Operationsfilesystemread_file, write_file, search
UI Testingplaywrightnavigate, click, screenshot
Issue Managementgithubcreate_issue, list_issues
CI/CDgithublist_workflows, get_job_logs

Access Control Configuration

Server-Level Access Control
json
{
  "mcpServers": {
    "filesystem": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y", "@modelcontextprotocol/server-filesystem",
        "/home/runner/work/cia/cia"
      ],
      "env": {
        "ALLOWED_OPERATIONS": "read,write,search"
      }
    }
  }
}
Directory Restrictions

Allowed directories should follow the principle of least privilege:

✅ /home/runner/work/cia/cia          — Project root
✅ /home/runner/work/cia/cia/src      — Source code
✅ /home/runner/work/cia/cia/.github  — CI/CD configuration

❌ /home/runner                        — Too broad
❌ /etc                                — System configuration
❌ /tmp                                — Temporary files (security risk)

Troubleshooting

Common Issues
IssueSymptomResolution
Server not starting"Failed to connect" errorCheck command path and args
Permission deniedTool call failsVerify filesystem paths and permissions
Token expiredAuthentication errorsRefresh environment variables
Version mismatchUnexpected tool behaviorPin and update package versions
TimeoutTool call hangsCheck network connectivity for SSE servers
Diagnostic Commands
bash
# Verify MCP config syntax
cat .github/copilot-mcp-config.json | python3 -m json.tool

# Check if MCP server binary is available
which github-mcp-server

# Test filesystem server
npx -y @modelcontextprotocol/server-filesystem --help

# Check environment variables
env | grep -i mcp
env | grep -i github_token

Configuration Validation Checklist

□ JSON syntax is valid
□ All server commands exist and are executable
□ Environment variables are properly referenced (not hardcoded)
□ Filesystem paths follow least privilege
□ Package versions are pinned
□ No secrets in configuration file
□ Configuration is committed to repository
□ Server definitions match documented architecture
□ Access control rules are documented

ISMS Alignment

Configuration AreaISO 27001NIST CSFCIS Controls
Access ControlA.8.3PR.AC-4CIS 6.1
Secret ManagementA.8.24PR.DS-1CIS 3.11
Configuration MgmtA.8.9PR.IP-1CIS 4.1
Audit LoggingA.8.15DE.AE-3CIS 8.2
Change ControlA.8.32PR.IP-3CIS 4.2

References

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/mcp-gateway-configuration of Hack23/cia.

Open the folder on GitHubat commit bbed538

Compare with similar skills

MCP Gateway Configuration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

MCP Gateway Configuration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
MCP Gateway Configuration this skillHack23/cia239—~1.8kAutomated safety check: PassApache-2.0
Project Releaseswimmwatch/cloakbrowser-mcp161—~1.9kAutomated safety check: PassMIT
Project Pull Requestswimmwatch/cloakbrowser-mcp161—~1kAutomated safety check: PassMIT
Deepwiki MCP Skillholon-run/uxc116—~700Automated safety check: PassMIT
Building MCP Server On CloudflareCommandCodeAI/agent-skills132—~1.5kAutomated safety check: PassMIT
Agentsbutterbase-ai/butterbase-skills5341 repos~1.8kAutomated safety check: PassMIT

Similar skills

  • Project Release

    swimmwatch/cloakbrowser-mcp

    Prepare, publish, verify, or recover a cloakbrowser-mcp release only when the user explicitly requests release work.

    161 GitHub stars~1.9k tokensUpdated 7 days ago
    Agent WorkflowsAuto-check passed
  • Project Pull Request

    swimmwatch/cloakbrowser-mcp

    Create, update, prepare, or review a cloakbrowser-mcp GitHub Pull Request only when the user explicitly requests PR work.

    161 GitHub stars~1k tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Deepwiki MCP Skill

    holon-run/uxc

    Ask questions and read documentation about any GitHub repository using DeepWiki MCP.

    116 GitHub stars~700 tokensUpdated 23 days ago
    Agent WorkflowsAuto-check passed
  • Building MCP Server On Cloudflare

    CommandCodeAI/agent-skills

    Builds remote MCP (Model Context Protocol) servers on Cloudflare Workers with tools, OAuth authentication, and production deployment.

    132 GitHub stars~1.5k tokensUpdated 7 mo ago
    Agent WorkflowsAuto-check passed
  • Agents

    butterbase-ai/butterbase-skills

    A skill your agent uses when designing, deploying, or debugging a Butterbase Agent (declarative LLM/tool graph), registering an MCP server for tool use, or wiring access controls and rate limits.

    534 GitHub starsUsed in 1 repo~1.8k tokens
    Agent WorkflowsAuto-check passed
  • Fastmcp Server

    davila7/claude-code-templates

    Complete guide for building MCP servers with FastMCP 3.0 - tools, resources, authentication, providers, middleware, and deployment.

    32k GitHub stars~1.9k tokensUpdated today
    Agent WorkflowsAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed

Questions about MCP Gateway Configuration

What does MCP Gateway Configuration do?

MCP gateway setup for multi-server integration, security configuration, tool routing, and access control. MCP Gateway Configuration is an agent skill from Hack23/cia.

When should I use MCP Gateway Configuration?

MCP Gateway Configuration fits situations like: tasks that involve MCP servers; tasks that involve Authorization and RBAC.

How do I install MCP Gateway Configuration in Claude Code?

Run `npx skills add Hack23/cia --skill mcp-gateway-configuration -a claude-code`. Or copy the skill folder (.github/skills/mcp-gateway-configuration in Hack23/cia) into .claude/skills/mcp-gateway-configuration in your project. Claude Code loads it when a task matches its description.

How do I install MCP Gateway Configuration in Codex?

Run `npx skills add Hack23/cia --skill mcp-gateway-configuration -a codex`. Or copy the skill folder (.github/skills/mcp-gateway-configuration in Hack23/cia) into .agents/skills/mcp-gateway-configuration in your project. Codex loads it when a task matches its description.

Can I use MCP Gateway Configuration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill mcp-gateway-configuration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mcp-gateway-configuration, .gemini/skills/mcp-gateway-configuration, .github/skills/mcp-gateway-configuration and .opencode/skills/mcp-gateway-configuration in your project.

What does MCP Gateway Configuration need to run?

Going by SKILL.md and its folder, MCP Gateway Configuration needs the command-line tools its instructions call (python3 and npx) and credentials named GITHUB_TOKEN and MCP_TOKEN. Our summary lists: Python 3; Node.js; A credential in MCP_TOKEN; A credential in GITHUB_TOKEN.

Does MCP Gateway Configuration access the network?

SKILL.md names 2 domains. As links in the text: modelcontextprotocol.io and docs.github.com. This is read from the text; nothing was executed.

Is MCP Gateway Configuration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does MCP Gateway Configuration use?

MCP Gateway Configuration is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does MCP Gateway Configuration use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to MCP Gateway Configuration?

Skills that share tags, products or a category with MCP Gateway Configuration: Project Release (swimmwatch/cloakbrowser-mcp, 161 stars), Project Pull Request (swimmwatch/cloakbrowser-mcp, 161 stars), Deepwiki MCP Skill (holon-run/uxc, 116 stars) and Building MCP Server On Cloudflare (CommandCodeAI/agent-skills, 132 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains MCP Gateway Configuration?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 7, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.