SkillAgentSearch skills...

cgw

CorpGateway Chrome Extension + MCP Server

Install / Use

claude mcp add ivsergeev -- npx -y github:ivsergeev/cgw

If the server publishes to npm under a different name, use that package instead — check the repo README.

About this skill
🔌

MCP Server

Model Context Protocol server

Quality Score

71/100

Supported Platforms

Claude Code
Claude Desktop

Tags

Our assessment of cgw

cgw scores 71/100 on our quality scale, 3777th of 4,588 Development & Engineering skills we index.

Its MCP Server is 14 KB long, well organised into 35 sections with 15 code examples: a thorough specification that gives an agent plenty to work with.

It has 3 GitHub stars, so there is little community track record yet; judge it on its content.

Substance
30/30
Structure
20/20
Description
8/15
Adoption
3/20
Freshness
11/15

Maintenance, license and trust

  • The repository was last updated about 5 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.
  • Our last check on 2026-09-12 found the source still online.
  • No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
  • Its trust signals score 73/100, with 3 cautions from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

cgw compared with similar skills

All 4 of these similar skills score higher than cgw; compare them before choosing.

SkillScoreStarsUpdatedFormat
cgw (this skill)by ivsergeev7135mo agoMCP Server
Agent-Reachby Panniantong10095.7k3d agoCLAUDE.md
headroomby headroomlabs-ai10075.0ktodayCLAUDE.md
CowAgentby zhayujie10047.3ktodayCLAUDE.md
ai-job-searchby MadsLorentzen10046.0k2d agoCLAUDE.md

Frequently asked questions

How do I install cgw?
Run claude mcp add ivsergeev -- npx -y github:ivsergeev/cgw. The install tabs above show the steps for each supported agent.
Which AI agents does cgw work with?
It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
Is cgw safe to use?
It declares no license and scores 73/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is cgw still maintained?
The repository was last updated about 5 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.

CorpGateway Extension + MCP Server

Русская версия

Chrome extension + MCP server for connecting AI agents to corporate systems via browser session. Capture endpoints from your real work, curate them into skills, and let the agent accumulate knowledge across sessions.

Installation Guide | Creating Custom Skills | Agent Knowledge Layer | Security

CorpGateway Extension

How It Works

┌──────────────────────────────────────────────────────────────┐
│                                                              │
│  AI Agent (OpenCode, Cursor, Claude Code)                    │
│       │                                                      │
│       │ POST /mcp (Bearer token)                             │
│       ▼                                                      │
│  ┌──────────┐    WebSocket     ┌───────────────────────┐     │
│  │ cgw_mcp  │◄────────────────►│  Chrome Extension     │     │
│  │ :9877    │                  │                       │     │
│  │          │                  │  • chrome.cookies     │     │
│  │ Tokens:  │                  │  • chrome.webRequest  │     │
│  │ • agent  │                  │  • fetch() w/ session │     │
│  │ • ext    │                  │  • Skill management   │     │
│  └──────────┘                  └───────────┬───────────┘     │
│                                            │                 │
│                                            │ fetch() + cookies/auth
│                                            ▼                 │
│                                   Corporate APIs             │
│                                   (Jira, Mattermost, ...)    │
└──────────────────────────────────────────────────────────────┘

Key advantage: the extension reuses your existing browser session for authorization. No need to store passwords, API keys, or configure OAuth — if you're logged into a corporate system in Chrome, the extension automatically uses that session.

Components

| Component | Description | Location | |-----------|-------------|----------| | Chrome Extension | Skill management, request execution via browser session | extension/ | | cgw_mcp | MCP server (HTTP + WebSocket daemon), bridge between agent and extension | cgw_mcp/ | | Presets | Ready-made skill sets for popular systems | presets/ |

Quick Start

1. Install the extension

  1. Open chrome://extensions
  2. Enable Developer mode
  3. Click Load unpacked → select the extension/ folder

2. Install and run cgw_mcp

cd cgw_mcp
npm install

As a daemon (autostart):

# Linux / macOS
./install.sh

# Windows (PowerShell)
.\install.ps1

Manually:

node index.js

On first run, a config file is created at ~/.corpgateway/cgw_mcp.json:

{
  "port": 9877,
  "token": "abc123...",
  "extensionToken": "def456...",
  "mcpInstructions": "..."
}

3. Connect the extension to cgw_mcp

  1. Extension icon → ⚙ Settings
  2. In the MCP Connection section:
    • Instance name: anything (e.g. "Chrome Work")
    • MCP server URL: http://localhost:9877
    • Extension token: copy extensionToken from ~/.corpgateway/cgw_mcp.json
  3. Click Save
  4. In the extension popup, click ⚡ Connect
  5. The extension icon turns colored — connection established

4. Import skills

  1. Extension settings → Import
  2. Select a file from presets/ (e.g. jira.json)
  3. Replace URL placeholders with your actual system addresses

5. Connect the AI agent

OpenCode + CorpGateway

Add to your agent config (opencode.json, .cursor/mcp.json, etc.):

{
  "mcp": {
    "corp": {
      "type": "remote",
      "url": "http://localhost:9877/mcp",
      "headers": {
        "Authorization": "Bearer <token from cgw_mcp.json>"
      }
    }
  }
}

MCP Tools

The agent receives the following meta-tools:

| Tool | Description | Parameters | |------|-------------|------------| | cgw_groups | List available groups | — | | cgw_list | List skills (all or by group); prepends the knowledge digest | group? | | cgw_schema | Get parameter details for a skill (includes confirm flag) | skill | | cgw_invoke | Invoke a skill (for skills with confirm=false) | skill, params? | | cgw_invoke_confirmed | Invoke a skill that requires confirmation (native mode only) | skill, params? | | cgw_recall | Search the knowledge base — facts, skill annotations, recipes | query?, kind?, tag?, limit? | | cgw_remember | Persist a new knowledge note | kind, title, body, tags?, skillName? | | cgw_update_note | Modify an existing note | id, plus any subset of fields | | cgw_forget | Delete a note | id |

Agent workflow

1. cgw_list                → sees org digest + skills grouped by purpose
2. cgw_recall(query=...)   → drills into details not covered by the digest
3. cgw_schema(skill=jira_issue) → sees parameters + confirm flag + which invoke to use
4. cgw_invoke(skill=jira_issue, params={key:"PROJ-1"}) → result (confirm=false)
   cgw_invoke_confirmed(skill=delete_issue, params={key:"PROJ-1"}) → result (confirm=true)
5. cgw_remember(...)       → saves a fact / annotation / recipe for the next session

Skill Configuration

Detailed guide: Creating Custom Skills (Русский)

Skill Editor

Via extension UI

Extension settings (chrome://extensions → CorpGateway → Details → Extension options):

  • Sidebar tabs: Skills / Recordings / Knowledge
  • Skills mode: groups in the sidebar, skill list in the center, edit form in the right panel
  • Recordings mode: named captures of your real portal usage that can be promoted into skills (see SKILLS.md)
  • Knowledge mode: the agent's long-running memory — digest + recallable notes (see KNOWLEDGE.md)

Skill structure

| Field | Description | |-------|-------------| | Name | Function name for the agent (e.g. jira_issue) | | Description | What the skill does (visible to agent) | | URL | API endpoint with path parameters {id} | | HTTP method | GET, POST, PUT, PATCH, DELETE | | Origin URL | Where to execute the request from (if different from URL) | | Body Template | JSON body template with {{param}} placeholders | | Response Filter | Dot-notation paths for response filtering | | HTTP headers | Custom headers (support {{param}}) | | Parameters | Name, type (String/Integer/Float/Boolean/Date), required, description |

Parameter substitution

| Location | Format | Example | |----------|--------|---------| | URL path | {param} | /api/issues/{key} → /api/issues/PROJ-1 | | Body | {{param}} | {"text":"{{msg}}"} → {"text":"Hello"} | | Headers | {{param}} | X-Data: {{token}} → X-Data: abc123 | | Query string | automatic | GET + remaining params → ?q=test&limit=10 |

Groups

Skills are organized into groups. Each group can be enabled/disabled — disabled groups and their skills are hidden from the agent.

Presets

Ready-made skill sets in presets/:

| File | System | Skills | |------|--------|--------| | jira.json | Jira REST API | issue, search, comments, transitions | | confluence.json | Confluence REST API | pages, search, spaces | | gitlab.json | GitLab API | projects, issues, merge requests | | mattermost.json | Mattermost API | channels, posts, users, search | | outlook.json | Microsoft Graph API | mail, calendar, contacts |

After import, replace URL placeholders (JIRA_URL, MATTERMOST_URL, etc.) with actual addresses.

Authorization

How the extension accesses APIs

  1. Cookies: chrome.cookies API — the extension has access to cookies for all permitted domains
  2. Authorization headers: chrome.webRequest.onSendHeaders — intercepts Authorization from all browser requests (Bearer tokens, JWT)
  3. Fetch with credentials: requests are executed from the extension's Service Worker with credentials: 'include'

You don't need to enter passwords or API keys. If you're logged into a corporate system in Chrome — the extension automatically uses that session.

Security

┌─────────────────────────────────────────────────────────┐
│  Layer 1: HTTP API (cgw_mcp)                            │
│  • Bearer token on every agent request                  │
│  • Timing-safe token comparison                         │
│  • Rate limiting: 10 attempts/min per IP                │
│  • localhost only — not accessible from network         │
│  • CORS restricted to localhost                         │
│  • JSON-RPC method whitelist                            │
│  • Message size limit (1 MB)                            │
│                                                         │
│  Layer 2: WebSocket (cgw_mcp ↔ extension)               │
│  • Extension token for authentication                   │
│  • Mutual auth: HMAC challenge-response                 │
│  • Both sides prove knowledge of extensionToken         │
│                                                         │
│  Layer 3: Chrome Extension                              │
│  • Sender validation — web pages cannot send            │
│    commands to the extension                            │
│  • SSRF protection: private IP blocking, http(s) only   │
│  • Template validation: JSON/HTTP injection protection  │
│  • MCP connection — only via user button click          │
│  • Notifications on auth session expiry                 │
│                                                         │
│  Layer 4: Data                                          │
│  • Credentials not stored — uses Chrome session         │
│  • Tokens in cgw_mcp.json with 0600 permissions         │
│  • Skills in chrome.storage.local (encrypted by Chrome) │
│  • Audit log: last 100 invocations in session storage   │
│  • Tokens masked in logs                                │
│  • Confirmation modes: native (agent permissions) or OTP │
└─────────────────────────────────────────────────────────┘

Configuration

cgw_mcp.json

Location: ~/.corpgateway/cgw_mcp.json

{
  "port": 9877,
  "token": "agent-token",
  "extensionToken": "exte…[redacted]",
  "mcpInstructions": "Instructions for the agent..."
}

| Field | Description | |-------|-------------| | port | HTTP port for cgw_mcp (default 9877) | | token | Bearer token for the agent | | extensionToken | Token for WebSocket connection from extension | | mcpInstructions | Instruction text sent to agent on MCP initialize |

Extension (Settings)

| Field | Description | |-------|-------------| | Instance name | Identification when using multiple browsers | | MCP server URL | HTTP address of cgw_mcp | | Extension token | extensionToken from cgw_mcp.json |

Managing cgw_mcp

Install as daemon

Windows:

cd cgw_mcp
.\install.ps1              # install (Task Scheduler)
.\install.ps1 -Uninstall   # remove

Linux:

cd cgw_mcp
./install.sh               # install (systemd user service)
./install.sh uninstall      # remove

systemctl --user status cgw-mcp
systemctl --user restart cgw-mcp
journalctl --user -u cgw-mcp -f

macOS:

cd cgw_mcp
./install.sh               # install (LaunchAgent)
./install.sh uninstall      # remove

launchctl list | grep cgw-mcp
tail -f ~/.corpgateway/logs/cgw_mcp_launchd.log

Logs

Location: ~/.corpgateway/logs/

Rotation: last 7 days are kept. Format:

[2026-04-01T10:30:15.123Z] INFO cgw_mcp started on http://localhost:9877
[2026-04-01T10:30:20.456Z] INFO Extension connected: "Chrome Work"
[2026-04-01T10:31:05.789Z] INFO → Agent request id=1 method=tools/call

API Reference

P

Truncated for display — read the full file on GitHub.

Related Skills

View on GitHub
GitHub Stars3
CategoryDevelopment
Updated4mo ago
Forks0

Languages

JavaScript

Trust signals

73/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

1 medium2 low1 info