Agent skill

MCP Gateway Security

by Hack23 in Hack23/cia

MCP gateway security patterns, token management, request validation, and audit logging for MCP communications

Apache-2.0Auto-check passedSecurity

Install MCP Gateway Security

skills CLI
$ npx skills add Hack23/cia --skill mcp-gateway-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia mcp-gateway-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/mcp-gateway-security .claude/skills/mcp-gateway-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mcp-gateway-security
GitHub stars
239
Token cost
~2.4k tokens
SKILL.md length
525 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

MCP gateway security patterns, token management, request validation, and audit logging for MCP communications

  • Tasks that involve MCP servers
  • SKILL.md covers Purpose, When to Use This Skill, Threat Model for MCP and Token Management, plus 6 more sections
  • Needs GITHUB_TOKEN
  • Tasks that involve Threat modeling

What it does

MCP Gateway Security is an agent skill from Hack23/cia. MCP gateway security patterns, token management, request validation, and audit logging for MCP communications

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering MCP servers and Threat modeling. It works with Model Context Protocol. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve MCP servers
  • Tasks that involve Threat modeling

Example prompts

  • “/mcp-gateway-security”

Requirements

  • A credential in GITHUB_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • modelcontextprotocol.io
    • owasp.org
    • docs.github.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

MCP Gateway Security loads about 2.4k tokens when it runs. Until then it costs about 33 tokens; SKILL.md has 525 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~33
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit 6a9797b, republished under its Apache-2.0 licence (© Hack23). 525 words, ~2,388 tokens.

Download SKILL.mdSave it as .claude/skills/mcp-gateway-security/SKILL.md (or your agent's skills folder).
name
mcp-gateway-security
description
MCP gateway security patterns, token management, request validation, and audit logging for MCP communications
license
Apache-2.0

MCP Gateway Security Skill

Purpose

This skill provides security patterns and best practices for securing MCP (Model Context Protocol) gateway communications in the CIA platform. It covers token management, request validation, audit logging, and threat mitigation for AI-assisted development workflows.

When to Use This Skill

Apply this skill when:

  • ✅ Hardening MCP gateway configurations
  • ✅ Managing tokens and credentials for MCP servers
  • ✅ Implementing request validation for MCP tool calls
  • ✅ Setting up audit logging for MCP communications
  • ✅ Conducting security reviews of MCP configurations
  • ✅ Responding to security incidents involving MCP
  • ✅ Assessing risks of new MCP server integrations

Do NOT use for:

  • ❌ Initial MCP setup (use mcp-gateway-configuration)
  • ❌ Application-level security (use secure-code-review)
  • ❌ Infrastructure security (use security-architecture-validation)

Threat Model for MCP

Attack Surface
┌──────────────────────────────────────────────┐
│                 Threat Vectors                │
├──────────────────────────────────────────────┤
│                                              │
│  ┌──────────┐    ┌──────────┐    ┌────────┐ │
│  │ Token     │    │ Prompt   │    │ Supply │ │
│  │ Theft     │    │ Injection│    │ Chain  │ │
│  └────┬─────┘    └────┬─────┘    └───┬────┘ │
│       │               │              │       │
│       ▼               ▼              ▼       │
│  ┌─────────────────────────────────────────┐ │
│  │         MCP Gateway                      │ │
│  └────┬────────────┬────────────┬──────────┘ │
│       │            │            │            │
│  ┌────▼────┐  ┌────▼────┐  ┌───▼─────┐     │
│  │ Unauth  │  │ Data    │  │ Lateral │     │
│  │ Access  │  │ Exfil   │  │ Movement│     │
│  └─────────┘  └─────────┘  └─────────┘     │
└──────────────────────────────────────────────┘
Threat Matrix
ThreatLikelihoodImpactMitigation
Token theft from configMediumCriticalEnvironment variables, secret managers
Prompt injection via toolsMediumHighInput validation, output sanitization
Supply chain attack on MCP packagesLowCriticalVersion pinning, integrity checks
Unauthorized file accessMediumHighDirectory restrictions, least privilege
Data exfiltration via MCP toolsLowHighOutput monitoring, allowed destinations
Privilege escalationLowCriticalRole-based access, capability limits

Token Management

Token Security Requirements
RequirementImplementationPriority
No hardcoded tokensEnvironment variables onlyCritical
Token rotationRegular rotation scheduleHigh
Least privilege scopesMinimal required permissionsCritical
Token encryption at restOS keychain or secret managerHigh
Token audit trailLog token usage, not valuesMedium
Secure Token Configuration
json
{
  "mcpServers": {
    "github": {
      "type": "stdio",
      "command": "github-mcp-server",
      "env": {
        "GITHUB_TOKEN": "${GITHUB_TOKEN}"
      }
    }
  }
}

Token Handling Rules:

✅ DO: Use environment variable references (${VAR_NAME})
✅ DO: Use GitHub Actions secrets for CI/CD tokens
✅ DO: Rotate tokens at least quarterly
✅ DO: Use fine-grained PATs with minimal scopes
✅ DO: Revoke tokens immediately when compromised

❌ DON'T: Hardcode tokens in configuration files
❌ DON'T: Commit tokens to version control
❌ DON'T: Share tokens between environments
❌ DON'T: Use classic PATs with broad scopes
❌ DON'T: Log token values in any log output
GitHub Token Scopes (Principle of Least Privilege)
MCP OperationRequired ScopeJustification
Read codecontents:readCode search and file reading
Create PRspull_requests:writePR creation and updates
Manage issuesissues:writeIssue creation and updates
Read workflowsactions:readCI/CD status checking
Security alertssecurity_events:readCodeQL and Dependabot

Request Validation

Input Validation for MCP Tools

File Operations:

Validation Rules:
1. Path must be within allowed directories
2. Path must not contain traversal sequences (../)
3. File extension must be in allowed list
4. File size must not exceed limits
5. Content must not contain known malicious patterns

Code Operations:

Validation Rules:
1. Branch names must match allowed pattern
2. Commit messages must not contain secrets
3. File content must pass security scanning
4. PR descriptions must not leak sensitive data
Output Sanitization
Before Returning MCP Tool Output:
1. Strip any credential-like patterns
2. Remove internal IP addresses/hostnames
3. Truncate excessively large outputs
4. Validate JSON/structured output format
5. Log sanitization actions for audit
Show full SKILL.md (231 more words)Show less
Dangerous Tool Patterns
ToolRiskMitigation
filesystem.write_fileOverwrite critical filesRestrict to project directories
filesystem.deleteData lossRequire confirmation, backup
github.push_filesInject malicious codeCode review before merge
playwright.evaluateExecute arbitrary JSSandbox, restrict domains
bash.executeSystem command executionAllowlist commands, sandbox

Audit Logging

What to Log
EventLog LevelData to Capture
MCP server start/stopINFOServer name, timestamp
Tool invocationINFOTool name, parameters (sanitized)
Authentication successINFOServer name, token type (not value)
Authentication failureWARNServer name, failure reason
Access deniedWARNTool, resource, reason
Configuration changeINFOWhat changed, who changed it
Error/exceptionERRORError details, stack trace
What NOT to Log
❌ Token values or API keys
❌ File contents containing secrets
❌ User passwords or credentials
❌ Full request/response bodies with PII
❌ Internal network topology details
Audit Log Format
json
{
  "timestamp": "2024-01-15T10:30:00Z",
  "event": "mcp.tool.invocation",
  "server": "github",
  "tool": "create_pull_request",
  "parameters": {
    "owner": "Hack23",
    "repo": "cia",
    "title": "[REDACTED]"
  },
  "result": "success",
  "duration_ms": 1250,
  "user": "copilot-agent"
}

Security Configuration Checklist

Pre-Deployment
□ All tokens use environment variables (never hardcoded)
□ Token scopes follow least privilege
□ Filesystem access restricted to project directory only
□ MCP package versions pinned to specific releases
□ Configuration file committed (without secrets)
□ No sensitive data in MCP server arguments
□ SSE server URLs use HTTPS only
□ Certificate validation enabled for remote servers
Periodic Review (Monthly)
□ Review token scopes — remove unnecessary permissions
□ Rotate tokens per schedule
□ Check for new MCP package versions and CVEs
□ Review audit logs for anomalies
□ Verify directory restrictions still appropriate
□ Test authentication failure handling
□ Review and update threat model
□ Check for deprecated MCP server versions
Incident Response
MCP Security Incident
    │
    ├─→ Token Compromise
    │   ├─→ Revoke token immediately
    │   ├─→ Rotate all related tokens
    │   ├─→ Review audit logs for unauthorized access
    │   └─→ Update token storage mechanism
    │
    ├─→ Unauthorized File Access
    │   ├─→ Review filesystem server configuration
    │   ├─→ Check for directory traversal attempts
    │   ├─→ Restrict filesystem paths
    │   └─→ Review accessed files for data exposure
    │
    ├─→ Supply Chain Attack
    │   ├─→ Pin to known-good version
    │   ├─→ Verify package integrity
    │   ├─→ Check for malicious tool behavior
    │   └─→ Report to MCP package maintainers
    │
    └─→ Prompt Injection
        ├─→ Review tool invocation logs
        ├─→ Identify injected content
        ├─→ Assess data exposure
        └─→ Update input validation rules

OWASP Agentic Security Alignment

OWASP Agentic RiskMCP Mitigation
Excessive AgencyRestrict tool capabilities, require confirmation
Tool MisuseInput validation, output monitoring
Privilege EscalationLeast privilege tokens, capability limits
Data LeakageOutput sanitization, logging controls
Insecure OutputValidate all MCP tool responses
Supply ChainPin versions, verify integrity

ISMS Alignment

Security AreaISO 27001NIST CSFCIS Controls
Token ManagementA.8.24, A.5.17PR.DS-1CIS 3.11
Access ControlA.8.3, A.8.5PR.AC-4CIS 6.1
Audit LoggingA.8.15DE.AE-3CIS 8.2
Input ValidationA.8.28PR.IP-12CIS 16.1
Configuration MgmtA.8.9PR.IP-1CIS 4.1
Incident ResponseA.5.24-A.5.27RS.MA-1CIS 17.1

References

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/mcp-gateway-security of Hack23/cia.

Open the folder on GitHubat commit 6a9797b

Compare with similar skills

MCP Gateway Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

MCP Gateway Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
MCP Gateway Security this skillHack23/cia239—~2.4kAutomated safety check: PassApache-2.0
Forensifyalexgreensh/repo-forensics187—~2.5kAutomated safety check: NotesCustom licence
Securing AI Systemstrilwu/secskills156—~2.9kAutomated safety check: PassMIT
Plugin Scanneriflytek/skillhub5.2k2 repos~1.1kAutomated safety check: NotesApache-2.0
Webcrypt MCPputervision/state-memory-mcp111—~847Automated safety check: PassMIT
Security Passcyanheads/pubmed-mcp-server154—~6.4kAutomated safety check: PassApache-2.0

Similar skills

  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    187 GitHub stars~2.5k tokensUpdated 10 days ago
    SecurityAuto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    156 GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Plugin Scanner

    iflytek/skillhub

    Scan AI agent skills, plugins, MCP servers, and agent tooling for prompt injection, unsafe commands, secret exposure, and supply-chain risks before installing or trusting them.

    5.2k GitHub starsUsed in 2 repos~1.1k tokens
    SecurityAuto-check: notes
  • Webcrypt MCP

    putervision/state-memory-mcp

    Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography.

    111 GitHub stars~847 tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Security Pass

    cyanheads/pubmed-mcp-server

    Review an MCP server for common security gaps: LLM-facing surfaces as injection vector (tools, resources, prompts, descriptions), scope blast radius, destructive ops without consent, upstream auth…

    154 GitHub stars~6.4k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Agent Bom Registry

    LeoYeAI/openclaw-master-skills

    MCP server security registry and trust assessment — look up servers in the 427+ server security metadata registry, run pre-install marketplace checks, batch fleet risk scoring, assess skill file…

    2.2k GitHub stars~969 tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Questions about MCP Gateway Security

What does MCP Gateway Security do?

MCP gateway security patterns, token management, request validation, and audit logging for MCP communications. MCP Gateway Security is an agent skill from Hack23/cia.

When should I use MCP Gateway Security?

MCP Gateway Security fits situations like: tasks that involve MCP servers; tasks that involve Threat modeling.

How do I install MCP Gateway Security in Claude Code?

Run `npx skills add Hack23/cia --skill mcp-gateway-security -a claude-code`. Or copy the skill folder (.github/skills/mcp-gateway-security in Hack23/cia) into .claude/skills/mcp-gateway-security in your project. Claude Code loads it when a task matches its description.

How do I install MCP Gateway Security in Codex?

Run `npx skills add Hack23/cia --skill mcp-gateway-security -a codex`. Or copy the skill folder (.github/skills/mcp-gateway-security in Hack23/cia) into .agents/skills/mcp-gateway-security in your project. Codex loads it when a task matches its description.

Can I use MCP Gateway Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill mcp-gateway-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mcp-gateway-security, .gemini/skills/mcp-gateway-security, .github/skills/mcp-gateway-security and .opencode/skills/mcp-gateway-security in your project.

What does MCP Gateway Security need to run?

Going by SKILL.md and its folder, MCP Gateway Security needs credentials named GITHUB_TOKEN. Our summary lists: A credential in GITHUB_TOKEN.

Does MCP Gateway Security access the network?

SKILL.md names 4 domains. As links in the text: modelcontextprotocol.io, owasp.org, docs.github.com and github.com. This is read from the text; nothing was executed.

Is MCP Gateway Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does MCP Gateway Security use?

MCP Gateway Security is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does MCP Gateway Security use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to MCP Gateway Security?

Skills that share tags, products or a category with MCP Gateway Security: Forensify (alexgreensh/repo-forensics, 187 stars), Securing AI Systems (trilwu/secskills, 156 stars), Plugin Scanner (iflytek/skillhub, 5.2k stars) and Webcrypt MCP (putervision/state-memory-mcp, 111 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains MCP Gateway Security?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.