Contro1 Action Gateway
Choose the applications your organization approves, decide who may do what, and connect one MCP. Every person and agent gets exactly their access, and every action is recorded on their name.
Platform
Write your organization's instructions for its agents once, push them to the whole company, a department, a person or one agent, and deliver them over MCP with versions, rollback and security scanning.
Updated Oct 8, 2026
A skill is your organization's own instructions for how work is done. Contro1 versions them, scans them, shows you who a change affects before you publish, and delivers them to every connected agent over MCP.
A skill is a SKILL.md file, with optional supporting files, that tells an agent how your organization wants something done: "refunds under $50 are approved, above that ask finance". It is the open Agent Skills format that Claude Code, Codex, Cursor and others already load, so a skill written in Contro1 is a normal skill.
A skill never grants anything. Whether an agent may send that email or issue that refund is decided by its grants and re-checked by Contro1 at the moment it acts. A skill that says "you may send from finance@" changes nothing about what the agent may do, and revoking a grant takes effect immediately even for an agent holding a day-old copy of its skills.
Contro1 works out, for each agent, which skills it has and at which version. That answer is deterministic: no model chooses it, so "what was this agent told on Tuesday" always has one answer.
An agent connected to the Contro1 MCP server then receives its skills four ways at once, because MCP clients differ in what they understand:
In Skills > Library, choose Push to agents on a skill. You can push it to four kinds of target, each following the current version or pinned to a specific one:
| Push to | Reaches | Typical use |
|---|---|---|
| Whole organization | Every agent | How we write to customers, security basics |
| Department | Agents serving that department | Finance procedures, support playbooks |
| Person | Agents acting for that person | A team lead's working conventions |
| One agent | That agent only | A production agent's exact procedure |
Saving creates a draft. Drafts reach nobody. Publishing is a separate step, and before it you see who will change (named, with department and owner), who is protected by a pin or a freeze, which agents actually loaded the skill in the last 30 days, what changed in the text, and what the security scan said.
A published version never changes. To roll back, open the version history and choose Restore this version: Contro1 creates a new version with exactly that content and opens the same publish preview, so a rollback is reviewed like any other change.
For an agent doing real work, freeze it in Skills > Agents. A frozen agent keeps exactly the versions it has until someone chooses Upgrade to current. Nothing restarts: the agent sees the change on its next sync.
Contro1 does not push into a running session. Instead, the next time the agent calls any Contro1 tool, the result carries a short note about what changed since it connected: a skill newly pushed to it (named once, with what it is for), a new version of a skill it was shown, or a new version of a skill it actually loaded (repeated until it reloads).
What the agent already read earlier in the conversation stays in its context; the reload replaces it. If the agent asks for the version number it saw when it connected, it receives the current version with a note saying this one replaces the old copy, never an error. Pinned and frozen agents are not affected by a publish at all.
Skills are instructions that run with your agents' access, and research on public skills found that about one in four contains a vulnerability. Contro1 scans every saved version, every import and every skill found on employees' machines, once per distinct skill.
| Engine | What it checks | Needs a key |
|---|---|---|
| Contro1 baseline | Remote scripts piped to a shell, prompt overrides, hidden instructions, credential files, exfiltration endpoints | No |
| NVIDIA SkillSpector (Apache-2.0) | Patterns, AST, taint tracking, YARA, dependency CVEs; a 0-100 risk score | No (optional AI review) |
| Cisco Skill Scanner (Apache-2.0) | YAML and YARA-X rules, behavioral dataflow | No |
If the source changes between the preview and the import, the import is refused and you preview again: what becomes a draft is always what you read.
1
A GitHub folder, a repository of skills, or a direct SKILL.md link.
2
Contro1 fetches over HTTPS and pins the exact commit.
3
All three engines run before anything is saved.
4
The content and the findings, side by side.
5
Imported as a draft. Publish it like any other skill.
People install skills themselves, into ~/.claude/skills, ~/.codex/skills, .cursor/skills and similar folders. Those change how their agents behave and nobody in the organization reviewed them. contro1 skills report finds them and reports them under the person's name, so they appear in Skills > Discovered on machines with their scan result and whether each is one of yours.
The command only reads. --dry-run shows exactly what would be sent, and --metadata-only sends names and fingerprints without content. From the Discovered view an administrator can read any reported skill and adopt it into the library as a draft.
Reading skills needs the skills:read scope (actions:read is also accepted for credentials issued earlier), or mcp:skills:read on a consented MCP connection.
| Surface | Call | Returns |
|---|---|---|
| MCP | skills/list, skills/get, resources/read | Skills and files under skill://contro1/, with sha256 digests |
| MCP | list_org_skills, get_org_skill | The same, as tools |
| MCP | prompts/list, prompts/get | One prompt per skill |
| HTTP | GET /api/centcom/v1/skills/manifest | Keys, versions and digests, no bodies; ETag |
| HTTP | GET /api/centcom/v1/skills/{key}/versions/{n} | SKILL.md, files and digest; only if assigned |
| HTTP | POST /api/centcom/v1/skills/inventory | Used by contro1 skills report |
| CLI | contro1 skills list | get | sync | report | The same, from a terminal |
No. A skill is guidance. Every Action is authorized by Contro1 when the agent calls it, from its grants and policies, whatever any skill says.
Yes. The connection instructions, the get_org_skill tool and the prompts work in every MCP client. Clients that do support SEP-2640 load the same skills natively.
Its next load returns the new version, and its next Contro1 tool call tells it which skill changed so it reloads. Pinned and frozen agents do not change.
Open the version history and choose Restore this version on the last good one. It is published as a new version through the same preview, so you see who it moves.
No. It shows the findings and asks the person publishing or pushing it to confirm by name. That confirmation, with their name and email, is recorded in the audit log.
No. It reads skill folders and sends what it found. Use --dry-run to see exactly what would be sent first.
Choose the applications your organization approves, decide who may do what, and connect one MCP. Every person and agent gets exactly their access, and every action is recorded on their name.
Three ways to connect an agent to Contro1, chosen by where the agent runs: in your own code, in an app with an MCP connector, or on a computer. Exact steps and request shapes for each.
Install and use the contro1 CLI to register AI agents, create approval requests, push AI inventory, retrieve evidence and traces, and test workflows before using the SDK or API.
Route selected Claude Code actions to a manager or other eligible reviewer before they run, with production deployment as a practical quickstart example.