Atlas / MCP servers / roddutra / Agent Gateway

Agent GatewayCAUTION

mcp/roddutra/agent-gateway

Provides per-subagent MCP access controls to Claude Code (or any MCP client) across all your MCPs and prevents context window bloat. Loads only 3 tools instead of all your MCP Server's tool definitions. Agents discover tools on-demand, only when needed. Control which servers and individual tools eac

Verdict
CAUTION
Grade
C
Trust score
75 /100
Exposed tools
16 10r · 4w · 2d
Transport
stdio · streamable-http
License
MIT
Stars
41
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) gateway that aggregates multiple MCP servers and provides policy-based access control for agents and subagents. Solves Claude Code's MCP context window waste by enabling on-demand tool discovery instead of loading all tool definitions upfront.

Status

  • ✅ M0: Foundation - Configuration, policy engine, audit logging, list_servers tool
  • ✅ M1: Core - Proxy infrastructure, get_server_tools, execute_tool, middleware, metrics, hot reload, OAuth support
  • 🚧 M2: Production - HTTP transport, health checks (planned)
  • 🚧 M3: DX - Single-agent mode, config validation CLI, Docker (planned)

Current Version: M1-Core Complete (with OAuth)

Table of Contents

  • Overview
  • Installation
  • Quick Start
  • Command-Line Options
  • Configuration File Discovery
  • Configuration
  • Usage
  • Gateway Tools
  • Security Considerations
  • Troubleshooting
  • Testing
  • Development
  • Architecture
  • Future Features
  • Documentation
  • Contributing
  • License
  • Support
  • Acknowledgments

Overview

The Problem

When multiple MCP servers are configured in development environments (Claude Code, Cursor, VS Code), all tool definitions from all servers load into every agent's and subagent's context window at startup:

  • 5,000-50,000+ tokens consumed upfront
  • 80-95% of loaded tools never used by individual agents
  • Context ne
Read from source at commit 1f7e6b2cb957OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (pypi)
claude mcp add agent-mcp-gateway -- None agent-mcp-gateway==0.2.5
03

Exposed tools (16)

10 read · 4 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
brave_local_searchreadSearch local businesses
brave_web_searchreadSearch the web using Brave
complex_toolreadA tool with many parameters
create_userwriteCreate a new user
delete_userdestructiveDelete a user
drop_tabledestructiveDrop a database table
get_userreadGet user by ID
get_usersreadList all users
list_directoryreadList directory contents
list_tablesreadList database tables
querywriteExecute SQL query
read_filereadRead file contents
simpleread
update_userwriteUpdate user details
write_filewriteWrite file contents
xread
04

Trust audit

CAUTIONgrade C · trust 75/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (20)

HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.env.example:9
POSTGRES_URL=postgresql://postgres:password@localhost:5432/mydb
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_user, drop_table
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
config/.mcp-gateway-rules.json.example
.mcp-gateway-rules.json.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
config/.mcp.json.example
.mcp.json.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
config/.mcp.test.json
.mcp.test.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
src/config/.mcp-gateway-rules.json.example
.mcp-gateway-rules.json.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
src/config/.mcp.json.example
.mcp.json.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/downstream-mcp-oauth-proxying.md:317
mcp_url="http://127.0.0.1:8000/mcp",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/downstream-mcp-oauth-proxying.md:325
url="http://127.0.0.1:8000/mcp",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/specs/m2-production.md:424
and not origin.startswith("http://127.0.0.1"):
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/specs/m2-production.md:541
base_url = "http://127.0.0.1:8000"
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
config/README.md:116
4. **admin** - Full access to all servers and tools
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/claude-code-subagent-mcp-limitations.md:261
5. Gateway checks rules: developer agent has full access (configured as `"*"`)
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/policy-rules-specification.md:108
### Example 1: Admin with Full Access
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/security-guide.md:193
- An "admin" agent exists with full access
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:291
If you use `${VAR_NAME}` syntax in `.mcp.json`, note that macOS GUI applications run in isolated environments without access to your shell's environment variables. For Claude Desktop and similar apps,
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:488
**Note on GUI Applications:** macOS GUI applications (Claude Desktop, etc.) run in isolated environments without access to shell environment variables. If using `${VAR_NAME}` syntax in `.mcp.json`, ad
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/quickstart-config.md:23
**Load environment variables:**
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/quickstart-config.md:30
export $(cat .env | xargs)
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/quickstart-config.md:34
If using `${VAR_NAME}` syntax in `.mcp.json`, macOS GUI applications don't access shell environment variables. Add API keys to the gateway's `env` object in your MCP client configuration instead. See
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 1f7e6b2cb957full audit observations/trust-audit/mcp-server/roddutra__agent-gateway.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-081f7e6b2cb957CAUTIONC75first audit
06

Questions

What is the Agent Gateway MCP server?

Provides per-subagent MCP access controls to Claude Code (or any MCP client) across all your MCPs and prevents context window bloat. Loads only 3 tools instead of all your MCP Server's tool definitions. Agents discover tools on-demand, only when needed. Control which servers and individual tools eac

What tools does Agent Gateway expose?

16 in total: 10 read-only, 4 that write, and 2 that can delete or overwrite (delete_user, drop_table). Every one is listed on this page with its risk.

Is Agent Gateway safe to connect to an agent?

With care. The audit graded it C (75/100) and found 20 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Agent Gateway need?

No credential environment variables were found in its source, so it appears to need none.

How does Agent Gateway run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as agent-mcp-gateway.

How current is this page?

The grade is for one exact copy of the source (1f7e6b2cb957), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement