Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    mcp oauth flow verifier

    1

    Deep spec-compliance audit for MCP OAuth 2.1, PKCE, and CIMD implementations to prevent auth bypass and SSRF.

    $17

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    mcp oauth flow verifier

    mcp oauth flow verifier

    Example session with this skill installed

    Review the OAuth flow in this MCP server. It uses CIMD for registration and validates tokens via a library call. Check if it handles the audience and issuer correctly per the MCP spec.

    • Read your context and instructions
    • Compiled the mcp oauth flow
    • Generated the document

    I have completed the OAuth flow audit for your MCP server implementation. The audit focused on the CIMD registration handler and the token verification middleware.

    MCP OAuth Flow Audit Report

    ComponentStatusFindingSpec Reference
    PKCE EnforcementPASSS256 is enforced; client correctly halts if code_challenge_methods_supported is missing.RFC 7636, MCP §4
    Audience BindingFAILServer uses jwt.decode() to read the aud claim before signature verification.MCP §5, Iron Rule 3
    CIMD SSRF GuardFAILMetadata fetch follows redirects without re-validating the resolved IP of each hop.MCP §2, Iron Rule 5
    Issuer ValidationPASSImplements the full four-branch logic, including rejection of advertised-but-missing iss.RFC 9207, MCP §6
    Token PassthroughPASSNo evidence of client tokens being forwarded to upstream resource APIs.MCP §5, Iron Rule 6

    Critical Finding: Audience Verification Bypass

    The middleware in auth/validator.ts:42 compares the token's aud claim against the fixed INTERNAL_RESOURCE_ID constant. However, it uses jwt.decode(), which does not verify the cryptographic signature. An attacker can forge a token with a matching aud claim and bypass authentication entirely.
    Recommendation: Replace jwt.decode() with jwt.verify() or an introspection call to the Authorization Server, ensuring the algorithm is pinned to RS256 to prevent algorithm confusion.

    Critical Finding: CIMD Redirect SSRF

    The fetcher in reg/metadata.ts:12 uses a standard HTTP client that follows redirects by default. While the initial URL is validated, a malicious client_id could redirect to http://169.254.169.254/latest/meta-data/ to leak cloud credentials.
    Recommendation: Disable automatic redirect following or implement a custom dialer that re-verifies the resolved IP address for every Location header in the chain.

    Next steps

    1. Update auth/validator.ts to use signature-verified token claims.
    2. Configure the CIMD fetcher to reject all redirects or re-validate every hop.
    3. Run mcp-prompt-injection-probe to verify the fix against live redirect payloads.

    mcp-oauth-flow-verifier.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Verify PKCE S256 enforcement and discovery-gate logic in MCP clients.Detect SSRF vulnerabilities in Client ID Metadata Document (CIMD) fetches.Identify audience-binding flaws and signature verification bypasses.Check for mix-up attack protections using RFC 9207 issuer validation.

    About this skill

    Most custom MCP servers claiming OAuth 2.1 support are technically non-compliant. A 2026 census found that over 96% of OAuth-enabled MCP servers contained at least one registration flaw, often due to blind trust in libraries or incomplete PKCE implementations. This skill performs a systematic, spec-level audit of your MCP server's authorization flow to ensure it meets the rigorous requirements of the MCP authorization spec, OAuth 2.1, and RFC 9207.

    What it does

    • PKCE enforcement audit verifies that S256 is enforced across all authorization code paths and that the client correctly refuses to proceed when metadata is missing.
    • Resource indicator validation checks that the server-side audience restriction is bound to a fixed canonical URI rather than request-derived values.
    • CIMD SSRF analysis inspects metadata fetch implementations for DNS rebinding, redirect-hop bypasses, and non-canonical IP encoding vulnerabilities.
    • Mix-up attack verification implements the four-branch decision table for issuer validation to prevent cross-AS impersonation.
    • Token handling check ensures the server never violates the MUST NOT rule for token passthrough to upstream services.

    How it works

    1. Transport analysis determines if the server uses an HTTP-based transport where the authorization spec applies.
    2. Metadata inspection audits the Protected Resource Metadata and AS discovery endpoints for RFC 8414 compliance.
    3. Registration flow audit evaluates Dynamic Client Registration (DCR) or Client ID Metadata Document (CIMD) implementations against known flaw patterns.
    4. Signature & Audience trace confirms that token claims are verified via JWKS/introspection before they are trusted for audience matching.

    Frameworks & tools

    This tool targets custom MCP servers and clients using HTTP transport. It references the MCP Authorization Spec, OAuth 2.1 (draft-15), RFC 7636 (PKCE), RFC 8707 (Resource Indicators), and RFC 9207 (Issuer Identifier).

    Why this beats prompting it yourself

    Generic AI audits often miss the critical gap between "OAuth library is present" and "OAuth is correctly configured." This skill enforces strict Iron Rules derived from recent flaw censuses, specifically checking for TOCTOU DNS rebinding in metadata fetches and algorithm confusion attacks that standard prompts ignore.

    Use cases

    • Auditing a new MCP server implementation for spec-correct OAuth 2.1 compliance before public release.
    • Reviewing an inherited codebase to determine if Dynamic Client Registration (DCR) is leaking internal endpoints via SSRF.
    • Generating a spec-mapped compliance checklist to provide as documentation for security reviews.

    Known limitations

    This is a static source and configuration review only. It does not perform live adversarial testing or probe for vulnerabilities in tool handlers unrelated to the OAuth flow.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 1 day ago

    • Passed all security checks, Safe to install

    Listed1 day ago

    What's inside

    Frequently Asked Questions