פיתוח · שרת MCP מקומי
Oauth Auditor
Scans MCP server auth code for OAuth 2.1 anti-patterns: token passthrough, missing audience.
מה ה-MCP Registry מציין
הרשומה כפי שפורסמה ב-MCP Registry הרשמי (נקרא ב-4 באוקטובר 2026), בגרסה האחרונה.
- שם במרשם
io.github.4hmetuyar/oauth-auditor- גרסה
- 0.1.2
- סטטוס
- פעיל
- קטגוריה
- פיתוח
- שכבת תעבורה
- stdio (תהליך מקומי)
- חבילה
- npm
- פורסם
- 28 בספטמבר 2026
- עודכן
- 28 בספטמבר 2026
- מפרסם
- 4hmetuyar (GitHub) · 26 שרתים עם דפים כאן
- מרחב שמות
- מרחב השמות אומת על ידי ה-MCP Registry דרך GitHub (github.com/4hmetuyar) · איך
- מאגר קוד
- github.com/GuardBee/guardbee-mcp (תיקייה packages/oauth-auditor)
- מקור
- הרשומה ב-API של המרשם
חבילות
| מרשם | חבילה | גרסה | שכבת תעבורה |
|---|---|---|---|
| npm | @guardbee/mcp-oauth-auditor | 0.1.2 | stdio |
איך מחברים את Oauth Auditor
Oauth Auditor רץ באופן מקומי מתוך חבילת Node.js שפורסמה במרשם npm: @guardbee/mcp-oauth-auditor, גרסה 0.1.2. הוא משתמש ב-MCP על גבי stdio, ולכן הלקוח מפעיל אותו כתוכנה ומתקשר איתו דרך קלט ופלט סטנדרטיים. כדי להריץ אותו צריך Node.js; לקוחות מפעילים אותו בדרך כלל עם npx - הפקודה המקובלת היא npx -y @guardbee/mcp-oauth-auditor@0.1.2.
בפורמט ה-JSON של mcpServers, שלקוחות MCP רבים לדסקטופ ולעורכי קוד קוראים, הרשומה נראית כך (מצייני מקום בסוגריים זוויתיים):
{
"mcpServers": {
"oauth-auditor": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-oauth-auditor@0.1.2"
]
}
}
}נגזר מהרשומה במרשם, ולא נבדק כאן. מה השרת עושה, ובאילו תנאים, נקבע על ידי המפרסם שלו; כדאי לבדוק את מאגר הקוד או את האתר שלו לפני שנותנים לו גישה לחשבונות או לקבצים שלך. איך מוסיפים שרת MCP לעוזר AI · לפני שמתחברים
עוד מ-4hmetuyar (GitHub)
| שרת | הרצה |
|---|---|
| Elicitation AuditorMCP elicitation anti-patterns: secrets in forms, third-party authorize URLs, credentials in URLs. | מקומי · stdio |
| Llm RedteamActive jailbreak/extraction/obfuscation red-teaming for live LLM endpoints. | מקומי · stdio |
| MCP Config AuditorScans Cursor/Claude/Windsurf/VS Code MCP configs for unpinned versions, secrets, typosquats. | מקומי · stdio |
| MCP Server AuditorScans MCP server tool definitions for excessive agency, injection sinks, hardcoded secrets. | מקומי · stdio |
| Memory Poisoning ScannerScans agent code for untrusted input poisoning persistent cross-session memory. | מקומי · stdio |
| Model ScannerScans ML model files (PyTorch, safetensors, Keras, ONNX) for supply-chain risks. | מקומי · stdio |
| Prompt Injection ScannerScans RAG content/scraped pages for indirect prompt injection. | מקומי · stdio |
| Prompt Leak ScannerCatches leaked credentials and PII in outbound LLM prompts. | מקומי · stdio |
| Rug Pull DetectorBaselines an MCP server's tools and detects tool-definition changes after approval. | מקומי · stdio |
| Secret ScannerScans files for leaked secrets and API keys. | מקומי · stdio |
| Security ProxyMCP gateway: many servers, one policy, lethal-trifecta blocking, PII masking, audit log. | מקומי · stdio |
| Security SuiteBundle of secret-scanner, dependency-auditor, ssl-inspector, and dns-intelligence. | מקומי · stdio |
עוד שרתים בקטגוריה פיתוח
| שרת | הרצה |
|---|---|
| Nvidia Nim MCPMCP server for NVIDIA NIM - 50+ LLMs, multimodal, image gen, embeddings, reranking. | מקומי · stdio |
| NytNYT MCP - wraps The New York Times Developer APIs (developer.nytimes.com) | מרוחק · HTTPבדיקה חיה: ✓ לחיצת יד |
| nyxoryAgent-to-agent cloud service: deploys and runs your apps and services - domains, logs, real status. | מרוחק ומקומי · HTTP ו-stdioבדיקה חיה: נדרשת התחברות |
| O360 MCPRun Offensive360 SAST scans (60+ languages) on local code; findings with file/line and fixes. | מקומי · stdio |
| ÓbitoChecks for indication of death of a person from the CPF, in official databases. Platform-hosted, no. | מרוחק · HTTPבדיקה חיה: ✓ לחיצת יד |
| Obra CtoLocal-first MCP that scores your codebase's build readiness. Your code never leaves your machine. | מקומי · stdio |
| Obscura MCPMCP server adapter for Obscura Rust headless browser - web scraping with anti-detection. | מקומי · stdio |
| Obscuraai MCP ServerGenerate visual AI automation workflows from any MCP client. No API key required. | מקומי · stdio |