remote-oauth-mcp-pentest
Installation
SKILL.md
Remote OAuth MCP Pentest
Authorized testing of remote MCP servers using browser/OAuth-style login. Read ../../SECURITY_RULES.md first — it overrides anything here.
Operating rules (non-negotiable)
- Authorized targets only. Confirm scope + named authorizer before phase 1.
- Read-only, non-destructive by default. Deny-by-default is the expected result of every negative test — a denial is a PASS, an allow is a FINDING.
- Never exfiltrate real secrets; report type + location + first4/last4 only.
- Server-side authorization is the control under test. Browser login proves identity, not tool authorization.
- Show the plan before running live probes.