Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    mcp oauth runtime test harness

    1

    Run bounded OAuth authorization and token-rejection tests for MCP resource servers to generate runtime evidence.

    $15

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    mcp oauth runtime test harness

    mcp oauth runtime test harness

    Example session with this skill installed

    Run the OAuth test suite against our staging MCP resource server at https://staging.api.mcp-dev.local/tools using the provided synthetic fixtures in examples/input.json.

    • Read your context and instructions
    • Compiled the mcp oauth runtime
    • Generated the document

    I have completed the runtime authorization test suite against the staging MCP resource server. The suite executed 1 positive control and 5 negative rejection cases using the scripts/probe.py harness.

    MCP Authorization Evidence Report

    Test Case IDRequirementInput ProvenanceExpected ResultActual ResultStatus
    TC-001Valid Token AccessFixture: valid_scoped_jwt200 OK200 OKPASS
    TC-002Expired Token RejectionFixture: expired_jwt_2024401 Unauthorized401 UnauthorizedPASS
    TC-003Insufficient ScopeFixture: read_only_jwt403 Forbidden403 ForbiddenPASS
    TC-004Mismatched AudienceFixture: cross_env_jwt401/403200 OKFAIL
    TC-005Missing Auth HeaderFixture: null_header401 Unauthorized401 UnauthorizedPASS
    TC-006Cross-Tenant AttemptFixture: tenant_b_jwt403 Forbidden403 ForbiddenPASS

    Observation Summary

    Critical Failure in TC-004: The server accepted a token intended for a different audience (audience claim mismatch). This indicates the JWT validation logic is not strictly checking the aud field.

    • Positive Control: TC-001 confirmed the endpoint is functional and reachable under normal conditions.
    • Credential Safety: All Authorization header values were scrubbed from the probe.py output.

    Next steps

    1. Update the JWT validation middleware on the resource server to enforce strict aud (audience) verification.
    2. Re-run the harness using a new synthetic token for TC-004 to confirm the fix.
    3. Review the server logs for TC-004 to see why the validation provider did not trigger a rejection.

    mcp-oauth-runtime-test-harness.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Validate MCP tool authorization by testing scope and audience rejections.Generate evidence reports for security compliance without leaking credentials.Identify misconfigured JWT validation middleware in MCP resource servers.Test cross-tenant isolation using synthetic cross-env tokens.

    About this skill

    The problem

    Manual testing of OAuth implementations in Model Context Protocol (MCP) servers is error-prone and often lacks negative control evidence. Developers frequently struggle to prove that resource servers correctly reject malformed, expired, or scoped-out tokens without accidentally exposing credentials in logs.

    What it does

    • Executes a suite of bounded HTTP tests against staging MCP resource servers using provided test fixtures.
    • Runs mandatory positive controls alongside negative test cases including expired, wrong-audience, and insufficient-scope tokens.
    • Generates repeatable authorization evidence using specialized probing scripts while strictly masking sensitive header values.
    • Identifies discrepancies between expected rejection codes and actual server responses to verify authorization logic.

    Frameworks & tools

    Model Context Protocol (MCP), Python (probe scripts), JWT, and OAuth 2.0 staging environments.

    Why this beats prompting it yourself

    A standard LLM lacks the discipline to enforce strict negative controls and will often hallucinate authorization success. This skill follows a rigid evidence protocol that prevents "false pass" results and ensures no credentials leak into your persistent reports or logs.

    Use cases

    • Verify an MCP server correctly enforces scopes for specific tool executions.
    • Generate runtime authorization evidence for internal security audits.
    • Test cross-tenant isolation by attempting resource access with valid but mismatched tokens.

    Known limitations

    Requires pre-supplied test tokens with verified provenance; it cannot bypass JWT signatures or automate initial OAuth login flows. Only targets staging environments.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 13 days ago

    • Passed all security checks, Safe to install

    Listed13 days ago

    What's inside

    Frequently Asked Questions