Scans MCP server auth code for OAuth 2.1 anti-patterns: token passthrough, missing audience
MCPpedia last refreshed this data
io.github.4hmetuyar/oauth-auditor is an MCP server that scans MCP server auth code for OAuth 2.1 anti-patterns: token passthrough, missing audience. Its tool list has not been published yet over stdio, requires no API key, and scores 55/100 on MCPpedia's security, maintenance and efficiency rubric.
Config is the same across clients - only the file and path differ.
{
"mcpServers": {
"io-github-4hmetuyar-oauth-auditor": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-oauth-auditor"
]
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
Scans MCP server auth code for OAuth 2.1 anti-patterns: token passthrough, missing audience
Run this in your terminal to verify the server starts. Then let us know if it worked - your result helps other developers.
npx -y '@guardbee/mcp-oauth-auditor' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories - click any category to see the underlying evidence.
No known CVEs.
Checked @guardbee/mcp-oauth-auditor against OSV.dev.
Be the first to review
Have you used this server?
Share your experience - it helps other developers decide.
Sign in to write a review.
Others in security / marketing
MCP server for JavaScript analysis, security auditing, browser automation and hooks
Deterministic security scanning, no model or API key, plus offline-verifiable proof a fix worked.
The only SEO skill your agent needs. 50+ SEO audit tools through a local CLI and MCP server, using your own crawl, Search Console, and GA4 data.
AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.
MCP Security Weekly
Get CVE alerts and security updates for io.github.4hmetuyar/oauth-auditor and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.