remote-oauth-mcp-pentest

Installation
SKILL.md

Remote OAuth MCP Pentest

Authorized testing of remote MCP servers using browser/OAuth-style login. Read ../../SECURITY_RULES.md first — it overrides anything here.

Operating rules (non-negotiable)

  • Authorized targets only. Confirm scope + named authorizer before phase 1.
  • Read-only, non-destructive by default. Deny-by-default is the expected result of every negative test — a denial is a PASS, an allow is a FINDING.
  • Never exfiltrate real secrets; report type + location + first4/last4 only.
  • Server-side authorization is the control under test. Browser login proves identity, not tool authorization.
  • Show the plan before running live probes.

Deliverables (produce all of these)

Installs
1
First Seen
Jul 1, 2026
remote-oauth-mcp-pentest — rwcod/mcp-remote-oauth-pentest-kit