Remote OAUTH MCP Pentest

Authorized security assessment of REMOTE MCP servers that use browser-based OAuth/OIDC login (Jira/Rovo-style). Drives an 18-phase review of the OAuth flow, discovery metadata, token validation, scope-to-tool mapping, per-tool and per-tenant authorization, API-token fallback, consent boundaries, and audit logging. Safe-by-default, read-only, deny-by-default. Use when auditing a remote MCP server reached over HTTP with an OAuth login step.

rwcod 2e46b97 10 files · 23.4 KB Updated

File contents

rwcod/mcp-remote-oauth-pentest-kit/tree/main/skills/remote-oauth-mcp-pentest commit 2e46b97669

Frequently asked questions

npx skillmds@latest add rwcod/remote-oauth-mcp-pentest