Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add deuriib/mcp-gateway --skill mcp-gwaygit clone --depth 1 https://github.com/deuriib/mcp-gatewayWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/deuriib/mcp-gateway/mcp-gway)<a href="https://agentmods.dev/skills/deuriib/mcp-gateway/mcp-gway"><img src="https://agentmods.dev/badge/skills/deuriib/mcp-gateway/mcp-gway/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/deuriib/mcp-gateway/mcp-gway"><img src="https://agentmods.dev/badge/skills/deuriib/mcp-gateway/mcp-gway.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00051 | $0.01958 |
| Opus 5 | $0.00026 | $0.00979 |
| Sonnet 5 | $0.00010 | $0.00392 |
| Haiku 4.5 | $0.00005 | $0.00196 |
Grade A, and why
mcp-gway scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -s http://127.0.0.1:8080/health | jq How it starts
The opening of the file, as written. The whole thing — 107 lines — stays where its author put it; the contents beside it link to each section on GitHub.
mcp-gway CLI — v2.2.0
Standalone Python CLI (mcp-gway = "mcp_gway.cli:main"). OpenCode format only.
Registry (servers/*.json + servers/*.pyi) is the single source of truth.
Commands (9)
| Command | Signature (from src/mcp_gway/cli.py) |
|---|---|
add |
mcp-gway add <name> --type local|remote [flags] |
remove |
mcp-gway remove <name> |
update |
mcp-gway update <name> --tools <csv> (--tools required) |
list |
mcp-gway list |
inspect |
mcp-gway inspect <name> |
serve |
mcp-gway serve [--transport stdio|http|sse] [--host 127.0.0.1] [--port 8080] [--log-level LEVEL] [--registry-dir PATH] (default stdio; --host/--port only with http|sse) |
refresh |
mcp-gway refresh [<name>] [--auth] [--oauth-port <port>] |
mcp |
mcp-gway mcp [--log-level LEVEL] [--registry-dir PATH] — DEPRECATED hidden alias: serve --transport stdio equiv mcp (mismo loop NDJSON y mismos args a _serve_stdio, modulo aviso de deprecacion en stderr solo mcp); prefer command: [mcp-gway, serve, --transport, stdio] for OpenCode type: local |
local-unrestricted |
mcp-gway local-unrestricted enable|disable|status — break-glass marker 72h (0o600), explicit only |
add — full flags (13, cli.py:45-95)
--type (required, click.Choice(["local","remote"])), --url, --command,
--tools (default "*"), --env KEY=VALUE (repeatable), --header KEY=VALUE
(repeatable, remote only), --oauth-client-id, --oauth-client-secret,
--oauth-scope, --timeout (int, default 5000 ms), --enabled/--no-enabled
(default enabled), --oauth-port (int, default 8989), --cwd.
# Remote — transport auto-detected (streamable-http → sse → http)
mcp-gway add youtube --type remote --url https://api.example.com/mcp
mcp-gway add supabase --type remote --url https://mcp.supabase.com/mcp --header "Authorization=Bearer TOKEN"
mcp-gway add supabase --type remote --url https://mcp.supabase.com/mcp --oauth-client-id ID --oauth-client-secret SECRET --oauth-scope "openid profile"
mcp-gway add api --type remote --url https://api.example.com/mcp --timeout 10000 --enabled
mcp-gway add api --type remote --url https://api.example.com/mcp --timeout 10000 --no-enabled
# Local — --command is ONE string, split via shlex
mcp-gway add filesystem --type local --command "npx -y @anthropic/mcp-filesystem"
mcp-gway add tools --type local --command "python -m my_mcp_server" --env MY_VAR=value --cwd /path/to/workdir
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed f26c7ee19e5c
- yesterday Changed · +11 lines · +5 tokens per session 13143ec4b06f
- 5d ago First seen · 96 lines · 46 tokens per session scan A b63d3c851c1c
mcp-gway is a skill published in the GitHub repository deuriib/mcp-gateway (0 stars, last pushed yesterday), licensed MIT. It adds 51 tokens to every session and 1,958 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-12.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
next-cache-components-adoption
Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…
next-cache-components-optimizer
Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…
next-partial-prefetching-adoption
Turn on Partial Prefetching in a Next.js app and work through the insights it surfaces. Use when the user wants to enable or adopt Partial Prefetching, flip the partialPrefetching flag, opt routes in with export const prefetch = 'partial', audit Link prefetch={true} behavior, preserve existing prefetched UI with…
chronicle
Analyze Copilot session history for standup reports, usage tips, session search, and session reindexing. Use when the user asks for a standup, daily summary, usage tips, workflow recommendations, wants to search or find past sessions by keyword/file/PR, wants to reindex their session store, or asks about deleting…