Agent♥︎Age
Catalog

io.github.4hmetuyar/elicitation-auditor

Official

by GuardBee · TypeScript

MCP elicitation anti-patterns: secrets in forms, third-party authorize URLs, credentials in URLs

io.github.4hmetuyar/elicitation-auditor MCP Server

This MCP server description focuses on “MCP elicitation anti-patterns,” specifically identifying security issues such as secrets in forms, third-party authorize URLs, and credentials embedded in URLs. It is intended to help developers recognize and address problematic patterns during MCP elicitation workflows.

🛠️ Key Features

  • Covers anti-patterns related to MCP elicitation
  • Highlights secrets in forms
  • Flags third-party authorize URLs
  • Notes credentials in URLs

🚀 Use Cases

  • Security review of MCP elicitation flows
  • Auditing data-handling and authorization URL patterns
  • Identifying where sensitive values may be exposed during elicitation

⚡ Developer Benefits

  • Clear focus on specific credential/secret exposure risks
  • Supports developer awareness of unsafe patterns like credentials in URLs

⚠️ Limitations

  • Available metadata does not list specific MCP tools, capabilities, or configuration options
  • No additional details (topics, toolCount, or readme excerpt) were provided

Topics

ai-securitykvkkmcpmcp-securitymodel-context-protocolowaspsecurity-scanner

Related servers

More in Security