Works with the AI tools you already use
mcp oauth runtime test harness
Run bounded OAuth authorization and token-rejection tests for MCP resource servers to generate runtime evidence.
$15
mcp oauth runtime test harness
Example session with this skill installed
Run the OAuth test suite against our staging MCP resource server at https://staging.api.mcp-dev.local/tools using the provided synthetic fixtures in examples/input.json.
- Read your context and instructions
- Compiled the mcp oauth runtime
- Generated the document
I have completed the runtime authorization test suite against the staging MCP resource server. The suite executed 1 positive control and 5 negative rejection cases using the scripts/probe.py harness.
MCP Authorization Evidence Report
| Test Case ID | Requirement | Input Provenance | Expected Result | Actual Result | Status |
|---|---|---|---|---|---|
| TC-001 | Valid Token Access | Fixture: valid_scoped_jwt | 200 OK | 200 OK | PASS |
| TC-002 | Expired Token Rejection | Fixture: expired_jwt_2024 | 401 Unauthorized | 401 Unauthorized | PASS |
| TC-003 | Insufficient Scope | Fixture: read_only_jwt | 403 Forbidden | 403 Forbidden | PASS |
| TC-004 | Mismatched Audience | Fixture: cross_env_jwt | 401/403 | 200 OK | FAIL |
| TC-005 | Missing Auth Header | Fixture: null_header | 401 Unauthorized | 401 Unauthorized | PASS |
| TC-006 | Cross-Tenant Attempt | Fixture: tenant_b_jwt | 403 Forbidden | 403 Forbidden | PASS |
Observation Summary
Critical Failure in TC-004: The server accepted a token intended for a different audience (audience claim mismatch). This indicates the JWT validation logic is not strictly checking the aud field.
- Positive Control: TC-001 confirmed the endpoint is functional and reachable under normal conditions.
- Credential Safety: All
Authorizationheader values were scrubbed from theprobe.pyoutput.
Next steps
- Update the JWT validation middleware on the resource server to enforce strict
aud(audience) verification. - Re-run the harness using a new synthetic token for TC-004 to confirm the fix.
- Review the server logs for TC-004 to see why the validation provider did not trigger a rejection.
mcp-oauth-runtime-test-harness.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The problem
Manual testing of OAuth implementations in Model Context Protocol (MCP) servers is error-prone and often lacks negative control evidence. Developers frequently struggle to prove that resource servers correctly reject malformed, expired, or scoped-out tokens without accidentally exposing credentials in logs.
What it does
- Executes a suite of bounded HTTP tests against staging MCP resource servers using provided test fixtures.
- Runs mandatory positive controls alongside negative test cases including expired, wrong-audience, and insufficient-scope tokens.
- Generates repeatable authorization evidence using specialized probing scripts while strictly masking sensitive header values.
- Identifies discrepancies between expected rejection codes and actual server responses to verify authorization logic.
Frameworks & tools
Model Context Protocol (MCP), Python (probe scripts), JWT, and OAuth 2.0 staging environments.
Why this beats prompting it yourself
A standard LLM lacks the discipline to enforce strict negative controls and will often hallucinate authorization success. This skill follows a rigid evidence protocol that prevents "false pass" results and ensures no credentials leak into your persistent reports or logs.
Use cases
- Verify an MCP server correctly enforces scopes for specific tool executions.
- Generate runtime authorization evidence for internal security audits.
- Test cross-tenant isolation by attempting resource access with valid but mismatched tokens.
Known limitations
Requires pre-supplied test tokens with verified provenance; it cannot bypass JWT signatures or automate initial OAuth login flows. Only targets staging environments.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 13 days ago
- Passed all security checks, Safe to install