Agentβ™₯︎Age
Catalog

io.github.GuardBee/oauth-auditor

Official

by GuardBee Β· TypeScript

Scans MCP server auth code for OAuth 2.1 anti-patterns: token passthrough, missing audience

GuardBee OAuth Auditor MCP Server

The io.github.GuardBee/oauth-auditor MCP server scans MCP server authentication code for OAuth 2.1 anti-patterns, focusing on issues such as token passthrough and missing audience. It is intended to help identify common problems in OAuth-related implementation within MCP servers.

πŸ› οΈ Key Features

  • Scans MCP server auth code
  • Detects OAuth 2.1 anti-patterns
  • Flags token passthrough
  • Flags missing audience

πŸš€ Use Cases

  • Reviewing MCP server OAuth authentication code for compliance issues
  • Auditing OAuth 2.1 implementations during development
  • Identifying token handling and audience configuration problems

⚑ Developer Benefits

  • Produces targeted findings related to OAuth 2.1 anti-patterns
  • Supports code review and debugging of authentication logic

⚠️ Limitations

  • Description only specifies scanning for token passthrough and missing audience; other checks are not stated.

Topics

ai-securitykvkkmcpmcp-securitymodel-context-protocolowaspsecurity-scanner

Related servers

More in Security