Works with the AI tools you already use
mcp oauth flow verifier
Deep spec-compliance audit for MCP OAuth 2.1, PKCE, and CIMD implementations to prevent auth bypass and SSRF.
$17
mcp oauth flow verifier
Example session with this skill installed
Review the OAuth flow in this MCP server. It uses CIMD for registration and validates tokens via a library call. Check if it handles the audience and issuer correctly per the MCP spec.
- Read your context and instructions
- Compiled the mcp oauth flow
- Generated the document
I have completed the OAuth flow audit for your MCP server implementation. The audit focused on the CIMD registration handler and the token verification middleware.
MCP OAuth Flow Audit Report
| Component | Status | Finding | Spec Reference |
|---|---|---|---|
| PKCE Enforcement | PASS | S256 is enforced; client correctly halts if code_challenge_methods_supported is missing. | RFC 7636, MCP §4 |
| Audience Binding | FAIL | Server uses jwt.decode() to read the aud claim before signature verification. | MCP §5, Iron Rule 3 |
| CIMD SSRF Guard | FAIL | Metadata fetch follows redirects without re-validating the resolved IP of each hop. | MCP §2, Iron Rule 5 |
| Issuer Validation | PASS | Implements the full four-branch logic, including rejection of advertised-but-missing iss. | RFC 9207, MCP §6 |
| Token Passthrough | PASS | No evidence of client tokens being forwarded to upstream resource APIs. | MCP §5, Iron Rule 6 |
Critical Finding: Audience Verification Bypass
The middleware in auth/validator.ts:42 compares the token's aud claim against the fixed INTERNAL_RESOURCE_ID constant. However, it uses jwt.decode(), which does not verify the cryptographic signature. An attacker can forge a token with a matching aud claim and bypass authentication entirely.
Recommendation: Replace jwt.decode() with jwt.verify() or an introspection call to the Authorization Server, ensuring the algorithm is pinned to RS256 to prevent algorithm confusion.
Critical Finding: CIMD Redirect SSRF
The fetcher in reg/metadata.ts:12 uses a standard HTTP client that follows redirects by default. While the initial URL is validated, a malicious client_id could redirect to http://169.254.169.254/latest/meta-data/ to leak cloud credentials.
Recommendation: Disable automatic redirect following or implement a custom dialer that re-verifies the resolved IP address for every Location header in the chain.
Next steps
- Update
auth/validator.tsto use signature-verified token claims. - Configure the CIMD fetcher to reject all redirects or re-validate every hop.
- Run
mcp-prompt-injection-probeto verify the fix against live redirect payloads.
mcp-oauth-flow-verifier.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Most custom MCP servers claiming OAuth 2.1 support are technically non-compliant. A 2026 census found that over 96% of OAuth-enabled MCP servers contained at least one registration flaw, often due to blind trust in libraries or incomplete PKCE implementations. This skill performs a systematic, spec-level audit of your MCP server's authorization flow to ensure it meets the rigorous requirements of the MCP authorization spec, OAuth 2.1, and RFC 9207.
What it does
- PKCE enforcement audit verifies that S256 is enforced across all authorization code paths and that the client correctly refuses to proceed when metadata is missing.
- Resource indicator validation checks that the server-side audience restriction is bound to a fixed canonical URI rather than request-derived values.
- CIMD SSRF analysis inspects metadata fetch implementations for DNS rebinding, redirect-hop bypasses, and non-canonical IP encoding vulnerabilities.
- Mix-up attack verification implements the four-branch decision table for issuer validation to prevent cross-AS impersonation.
- Token handling check ensures the server never violates the MUST NOT rule for token passthrough to upstream services.
How it works
- Transport analysis determines if the server uses an HTTP-based transport where the authorization spec applies.
- Metadata inspection audits the Protected Resource Metadata and AS discovery endpoints for RFC 8414 compliance.
- Registration flow audit evaluates Dynamic Client Registration (DCR) or Client ID Metadata Document (CIMD) implementations against known flaw patterns.
- Signature & Audience trace confirms that token claims are verified via JWKS/introspection before they are trusted for audience matching.
Frameworks & tools
This tool targets custom MCP servers and clients using HTTP transport. It references the MCP Authorization Spec, OAuth 2.1 (draft-15), RFC 7636 (PKCE), RFC 8707 (Resource Indicators), and RFC 9207 (Issuer Identifier).
Why this beats prompting it yourself
Generic AI audits often miss the critical gap between "OAuth library is present" and "OAuth is correctly configured." This skill enforces strict Iron Rules derived from recent flaw censuses, specifically checking for TOCTOU DNS rebinding in metadata fetches and algorithm confusion attacks that standard prompts ignore.
Use cases
- Auditing a new MCP server implementation for spec-correct OAuth 2.1 compliance before public release.
- Reviewing an inherited codebase to determine if Dynamic Client Registration (DCR) is leaking internal endpoints via SSRF.
- Generating a spec-mapped compliance checklist to provide as documentation for security reviews.
Known limitations
This is a static source and configuration review only. It does not perform live adversarial testing or probe for vulnerabilities in tool handlers unrelated to the OAuth flow.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 1 day ago
- Passed all security checks, Safe to install
Needs access to