Works with the AI tools you already use
mcp gateway config auditor
Independent configuration audit for MCP gateways to verify auth, rate-limiting, and multi-tenant isolation.
$15
mcp gateway config auditor
Example session with this skill installed
Audit my Kuadrant MCP gateway config. I've attached the AuthPolicy, the rate-limit CRD, and a sample of our JSON logs. We need to ensure Tenant A cannot exhaust Tenant B's tool budget.
- Read your context and instructions
- Compiled the mcp gateway config
- Generated the document
I have audited the Kuadrant configuration artifacts provided. The review focused on auth logic, rate-limit scoping, and tenant isolation provenance.
MCP Gateway Audit Findings
| Severity | Finding | Impact | Iron Rule Violation |
|---|---|---|---|
| High | Token Passthrough (Merged) | Bypasses per-tenant rate limits and breaks log attribution. | Rule 5, Rule 2 |
| High | Isolation Theatre | Tenant ID is read from a header (x-tenant-id) rather than a verified JWT claim. | Rule 3 |
| Medium | Global Rate-Limit Only | RateLimitPolicy lacks a domain key for per-tenant budgeting. | Rule 4 |
| Low | Log Identity Opacity | Logs record the Gateway service account GUID instead of the resolved user UPN. | Rule 6 |
Analysis
The root issue is the AuthPolicy configuration on the /v1/tools route. It validates the JWT signature but forwards the raw token to downstream servers without extracting and injecting the tenant_id into the context. Consequently, the rate-limiter sees aggregate traffic instead of individual tenant streams. Additionally, the admin UI at /admin/stats has no AuthPolicy attached, leaving gateway metrics exposed to the public internet.
Next steps
- Update the
AuthPolicyto use CEL expressions that verify theroleclaim. - Map the
tenant_idrate-limit descriptor to theauth.claims.tenantmetadata. - Apply an explicit
AUTH_REQUIREDpolicy to the/adminand/metricsroutes.
Corrected Configuration (Remediation)
# Fixed RateLimitPolicy for per-tenant scoping
apiVersion: kuadrant.io/v1beta2
kind: RateLimitPolicy
metadata:
name: mcp-tenant-limits
spec:
targetRef:
group: gateway.networking.k8s.io
kind: HTTPRoute
name: mcp-tools-route
limits:
"per-tenant-quota":
rates:
- limit: 100
window: 1m
counters:
- metadata:
- key: auth.claims.tenant # Pulls from verified token, not header
mcp-gateway-config-auditor.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
MCP gateways often suffer from "theatre of security" where policies exist but enforce nothing. An AuthPolicy that checks identity but ignores roles, or a tenant isolation check that trusts a caller-supplied header, leaves your infrastructure exposed. This skill provides a static configuration audit for deployed MCP proxies like Kuadrant, IBM mcp-context-forge, Kong, or Traefik Hub to find these gaps before they are exploited.
What it does
- Route Enumeration identifies every exposed endpoint, including often-missed admin UIs, metrics, and documentation paths.
- Policy Logic Audit reads actual CEL expressions and rules to ensure they enforce specific roles, not just presence of identity.
- Isolation Trace follows tenant identifiers to their source to verify they originate from trusted tokens rather than request arguments.
- Rate-Limit Scoping validates whether limits apply per-tenant, per-tool, or globally to prevent resource exhaustion.
- Log Attribution Review samples log schemas to ensure resolved caller identities are recorded instead of opaque gateway credentials.
How it works
- Establish Scope by listing available policy files, environment variables, and log samples for the specific gateway product.
- Execute Audit across auth, rate-limiting, isolation, and logging surfaces using the MCP specification checklist.
- Cross-Check Findings to merge related issues, such as token passthrough defeating both rate limits and logging simultaneously.
- Generate Remediation (paid tier) with corrected configuration patches and a pre-deployment sign-off checklist.
Frameworks & tools
Works with any MCP gateway or AI proxy supporting policy-based configuration, including Kuadrant, IBM mcp-context-forge, Kong AI Gateway, and Traefik Hub.
Why this beats prompting it yourself
Generic prompts often miss the "shared root cause" problem where one configuration flaw invalidates multiple security layers. This skill uses a specialized seven-layer isolation model and a specific 2026 incident database to catch combined vulnerabilities like CORS wildcarding paired with unauthenticated passthrough endpoints.
Use cases
- Reviewing gateway configuration before a production go-live to ensure multi-tenant isolation.
- Auditing a deployment after an identity provider change to verify token claims are still mapped correctly.
- Troubleshooting why logs cannot attribute specific tool calls to individual users or tenants.
Known limitations
Does not perform live adversarial testing or dynamic probing. Does not audit the source code of the underlying MCP servers or recommend switching between gateway products.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 2 days ago
- Passed all security checks, Safe to install