Stepgate
Agents can't skip steps: an MCP server that runs gated, API-only stepfiles on the client's own model.
Install / Use
claude mcp add Chaarangan -- npx -y github:Chaarangan/StepgateIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
AutomationSupported Platforms
Tags
Our assessment of Stepgate
Stepgate scores 73/100 on our quality scale, 2378th of 2,867 Automation skills we index.
Its MCP Server is 17 KB long, well organised into 18 sections with 4 code examples: a thorough specification that gives an agent plenty to work with.
It has 10 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated yesterday, so Stepgate is actively maintained.
- It is released under the Apache-2.0 license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 97/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-10-01. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
Stepgate compared with similar skills
All 4 of these similar skills score higher than Stepgate; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| Stepgate (this skill)by Chaarangan | 73 | 10 | 1d ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 87.2k | 16d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.2k | today | CLAUDE.md |
| rufloby ruvnet | 100 | 73.6k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.2k | today | CLAUDE.md |
Frequently asked questions
- How do I install Stepgate?
- Run
claude mcp add Chaarangan -- npx -y github:Chaarangan/Stepgate. The install tabs above show the steps for each supported agent. - Which AI agents does Stepgate work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is Stepgate safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is Apache-2.0-licensed and scores 97/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is Stepgate still maintained?
- The repository was last updated yesterday, so Stepgate is actively maintained.
Skill content
View source on GitHub<a id="readme-top"></a>
<div align="center"> <img src="docs/images/banner.svg" alt="Stepgate: agents can't skip steps" width="100%" /> <p align="center">[![CI][ci-shield]][ci-url] [![npm][npm-shield]][npm-url] [![Stargazers][stars-shield]][stars-url] [![Issues][issues-shield]][issues-url] [![License: Apache-2.0][license-shield]][license-url]
</p> <p align="center"> Write an agent's procedure once, as a YAML stepfile, and every step is gated. <br /> <a href="docs/stepfile.md"><strong>Read the stepfile format »</strong></a> <br /> <br /> <a href="#quick-start">Quick start</a> · <a href="awesome-stepfiles/">Browse the catalog</a> · <a href="https://github.com/Chaarangan/stepgate/issues/new?template=bug_report.yml">Report a bug</a> · <a href="https://github.com/Chaarangan/stepgate/issues/new?template=feature_request.yml">Request a feature</a> </p> </div> <details> <summary>Table of contents</summary> <ol> <li> <a href="#about-the-project">About the project</a> <ul> <li><a href="#why">Why</a></li> <li><a href="#built-with">Built with</a></li> </ul> </li> <li> <a href="#getting-started">Getting started</a> <ul> <li><a href="#prerequisites">Prerequisites</a></li> <li><a href="#quick-start">Quick start</a></li> </ul> </li> <li> <a href="#usage">Usage</a> <ul> <li><a href="#a-stepfile">A stepfile</a></li> <li><a href="#make-the-procedure-you-already-wrote-enforceable">Make the procedure you already wrote enforceable</a></li> <li><a href="#create-your-stepfile">Create your stepfile</a></li> <li><a href="#command-line">Command line</a></li> </ul> </li> <li><a href="#catalog">Catalog</a></li> <li><a href="#documentation">Documentation</a></li> <li> <a href="#contributing">Contributing</a> <ul> <li><a href="#contributors">Contributors</a></li> </ul> </li> <li><a href="#license">License</a></li> <li><a href="#contact">Contact</a></li> <li><a href="#acknowledgments">Acknowledgments</a></li> </ol> </details>About the project
Agents can't skip steps. The agent moves on only when a mechanical check passes, never on its own word. Stepgate is for anyone running agents on procedures where a skipped step or an invented value costs something, such as a cited research report, a CVE triage or a ticket written to Jira.
One file runs anywhere. A stepfile has no packages, no versions to pin and no code to deploy, so it moves as a single file to any MCP client, such as Claude Code, Cursor or an agent you wrote, and runs on the model that client already uses.
A stepfile declares its inputs, the remote APIs and MCP servers it may call, and an ordered list of steps. Each step says what output it must produce and which gates check that output. The file names no model and no framework.
Stepgate runs stepfiles. It is an MCP server that offers each stepfile as a tool. When a client's agent calls it, Stepgate shows the agent one step at a time, makes every API call the step needs, and moves on only when the step's gates pass.
Why
When an agent is handed a plan as text, it decides how much of the plan to follow, a step counts as done when the agent says so, and nothing records afterwards what actually ran. A stepfile moves those decisions out of the model:
- Steps run in order, one at a time. The agent is shown only the current step's instructions and operations, never a later step, so it cannot skip ahead. Earlier steps stay in its own conversation.
- Gates decide, not the model. A step passes only when its output satisfies JSON Schema, JSONLogic or an HTTP verifier, and gates can check that output against what the APIs actually returned, so a fabricated value fails. A failed gate's diagnosis goes back to the model for a bounded number of retries.
- The model judges, the server computes. A mechanical step makes its API calls and builds its output from a template, with no model involved, and a derived field fills in a count or a lookup after the model submits. The model is left the work that needs judgement.
- Writes wait for a person. An approve gate asks a person to confirm a step's output through an MCP elicitation before a later mechanical step writes it, so what reaches Jira is what the person saw (which clients show the form).
- The model never holds a key. The server makes every tool call and attaches credentials itself, and it refuses requests to hosts the stepfile does not declare.
- Every run leaves a record. A hash-chained ledger lists each step, tool call, gate verdict and retry, and editing it afterwards breaks the chain, which
stepgate --verifydetects. - Nothing to install on the client side. Stepfiles call remote APIs only, and the client adds one MCP server to its configuration. Stepgate needs no model key: the client's own model does the reasoning, and the same file gives the same path through its steps whichever model that is.
Built with
- [![TypeScript][typescript-shield]][typescript-url]
- [![Node.js][node-shield]][node-url]
- [![Model Context Protocol][mcp-shield]][mcp-url]
- [![JSON Schema][jsonschema-shield]][jsonschema-url] with Ajv
- [![JSONLogic][jsonlogic-shield]][jsonlogic-url]
Getting started
Prerequisites
- An MCP client, such as Claude Code, Claude Desktop, Cursor or VS Code.
- Node.js 22.18 or later, so the client can start Stepgate with
npx. - The credentials your stepfile declares. The
market-researchexample below needs a Tavily API key.
Quick start
-
Add the server to your MCP client's configuration, naming one or more stepfiles from the catalog, or giving absolute paths to your own
.stepfile.yamlfiles (details):{ "mcpServers": { "stepgate": { "command": "npx", "args": ["-y", "stepgate", "market-research"], "env": { "TAVILY_API_KEY": "tvly-..." } } } } -
The client sees a
market-researchtool. Ask your agent to run it for{ "brand": "Oatly", "market": "UK plant-based milk" }. -
The agent works through four steps (search, filter, analyse, report) with
stepgate_callandstepgate_submit, and the run ends with every step's output.
docs/connect.md has the configuration for Claude Code, Claude Desktop, Cursor, VS Code and other clients.
Every server also offers tools for writing stepfiles: ask your agent to write one for your use case, and it can read the format, inspect the APIs, validate its draft and try it through Stepgate (details).
<p align="right">(<a href="#readme-top">back to top</a>)</p>Usage
A stepfile
stepgate: "1"
id: market-research
inputs:
type: object
required: [brand, market]
properties:
brand: { type: string }
market: { type: string }
credentials:
tavily:
kind: bearer
hosts: [mcp.tavily.com]
description: Web search, used only by the search step.
tools:
tavily:
mcp: { url: "https://mcp.tavily.com/mcp/" }
credential: tavily
exposes: [{ name: tavily_search, effect: read }]
steps:
- id: search
tools: [tavily_search]
instructions: |
Run at least six searches about {{inputs.brand}} in {{inputs.market}}.
Submit every result as a source with an id of the form S-01.
produces:
type: object
required: [sources]
properties:
sources: { type: array }
gates:
- id: enough-sources
schema: { properties: { sources: { minItems: 12 } } }
- id: domain-breadth
message: Sources must span at least six distinct domains.
predicate:
">=":
- { length: { unique: { map: [{ var: output.sources }, { host: { var: url } }] } } }
- 6
retries: 2
# ... filter, analyse and report steps
Credentials say what is needed, never where it lives: the server reads tavily from TAVILY_API_KEY. effect: read marks the search as safe to retry. The complete file is awesome-stepfiles/marketing/market-research, and editors that support yaml-language-server validate against server/schema/stepfile.schema.json, which the npm package also ships.
Make the procedure you already wrote enforceable
A skill or runbook written as markdown tells an agent what to do, and the agent decides how much of it to follow. Here is one:
---
name: package-notes
description: Writes an upgrade note for each npm package, with versions taken from the registry.
---
1. Look up each package's latest version on the npm registry.
2. Write a one-line upgrade note for each. Never state a version the registry did not return.
stepgate_outline turns it into a skeleton, and the finished stepfile makes both lines binding. Stepgate does the lookup itself, so the agent never fetches or copies a version. The agent only writes the notes, and a gate rejects any note whose version differs from what the registry returned, naming the rows that broke it.
stepgate: "1"
id: package-notes
description: Writes an upgrade note for each npm package, with versions taken from the registry.
inputs:
type: object
required: [packages]
properties:
packages: { type: array, minItems: 1, maxItems: 20, items: { type: string, pattern: "^[a-z0-9][a-z0-9._-]*$" } }
tools:
npm:
openapi:
server: https://registry.npmjs.org
document:
openapi: 3.1.0
info: { title: npm registry, version: "1" }
paths:
/{name}/latest:
get:
operationId: getLatest
parameters: [{ name: name, in: path, required: true, schema: { type: string } }]
exposes: [getLatest]
steps:
- id: look-up
do:
calls:
- id: latest
operation: getLatest
each: { var: inputs.packages }
arguments: { name: { var: item } }
output:
packages: { map: [{ var: responses.latest }, { object: [[name, { var: name }], [latest, { var: version }]] }] }
produces:
type: object
required: [packages]
properties: { packages: { type: array } }
- id: notes
instructions: |
Write a one-line upgrade note for each of these packages, saying what
its latest version is and whether that is a new major version:
{{steps.look-up.packages}}
produces:
type: object
required: [notes]
properties:
notes:
type: array
items:
type: object
required: [name, latest, note]
properties: { name: { type: string }, latest: { type: string }, note: { type: string } }
gates:
- id: versions-from-registry
message: Every note must give the version the registry returned for its package.
predicate:
none:
- join: [{ var: output.notes }, { var: steps.look-up.packages }, name, name]
- or: [{ "==": [{ var: right }, null] }, { "!=": [{ var: left.latest }, { var: right.latest }] }]
retries: 2
</details>
Create your stepfile
Ask your coding assistant for one in plain words. With Stepgate connected, it reads the format, inspects the API, validates its draft and tries it:
Write a stepfile that converts an amount between currencies at the latest ECB rate,
using the Frankfurter API. Try it with 250 USD to EUR.
For the full prompt
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
87.2kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.2kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ruflo
73.6k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
CowAgent
47.2kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
