Developer · Local MCP server
Oauth Auditor
Scans MCP server auth code for OAuth 2.1 anti-patterns: token passthrough, missing audience.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.4hmetuyar/oauth-auditor- Version
- 0.1.2
- Status
- Active
- Category
- developer
- Transport
- stdio (local process)
- Package
- npm
- Published
- 2026-09-28
- Updated
- 2026-09-28
- Publisher
- 4hmetuyar (GitHub) · 26 servers with pages here
- Repository
- github.com/GuardBee/guardbee-mcp (folder packages/oauth-auditor)
- Source
- Registry API entry
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| npm | @guardbee/mcp-oauth-auditor | 0.1.2 | stdio |
How to connect Oauth Auditor
Oauth Auditor runs locally from a Node.js package published to the npm registry: @guardbee/mcp-oauth-auditor version 0.1.2. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y @guardbee/mcp-oauth-auditor@0.1.2.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"oauth-auditor": {
"command": "npx",
"args": [
"-y",
"@guardbee/mcp-oauth-auditor@0.1.2"
]
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More from 4hmetuyar (GitHub)
| Server | Runs |
|---|---|
| Elicitation AuditorMCP elicitation anti-patterns: secrets in forms, third-party authorize URLs, credentials in URLs. | Local · stdio |
| Llm RedteamActive jailbreak/extraction/obfuscation red-teaming for live LLM endpoints. | Local · stdio |
| MCP Config AuditorScans Cursor/Claude/Windsurf/VS Code MCP configs for unpinned versions, secrets, typosquats. | Local · stdio |
| MCP Server AuditorScans MCP server tool definitions for excessive agency, injection sinks, hardcoded secrets. | Local · stdio |
| Memory Poisoning ScannerScans agent code for untrusted input poisoning persistent cross-session memory. | Local · stdio |
| Model ScannerScans ML model files (PyTorch, safetensors, Keras, ONNX) for supply-chain risks. | Local · stdio |
| Prompt Injection ScannerScans RAG content/scraped pages for indirect prompt injection. | Local · stdio |
| Prompt Leak ScannerCatches leaked credentials and PII in outbound LLM prompts. | Local · stdio |
| Rug Pull DetectorBaselines an MCP server's tools and detects tool-definition changes after approval. | Local · stdio |
| Secret ScannerScans files for leaked secrets and API keys. | Local · stdio |
| Security ProxyMCP gateway: many servers, one policy, lethal-trifecta blocking, PII masking, audit log. | Local · stdio |
| Security SuiteBundle of secret-scanner, dependency-auditor, ssl-inspector, and dns-intelligence. | Local · stdio |
More developer servers
| Server | Runs |
|---|---|
| nyxoryAgent-to-agent cloud service: deploys and runs your apps and services — domains, logs, real status. | Remote & Local · HTTP, stdio |
| O'Reilly Expert MCP ServerGrounded, citable answers to tech questions from O'Reilly's library. Requires Expert MCP access. | Remote · HTTP |
| O'Reilly Media MCP ServerSearch O'Reilly for tech books, courses, events, and more. Requires an O'Reilly subscription. | Remote · HTTP |
| O360 MCPRun Offensive360 SAST scans (60+ languages) on local code; findings with file/line and fixes. | Local · stdio |
| ObelinfMCP server for Obelinf, the network documentation platform. Sites, racks, devices, IPs, VLANs. | Remote · HTTP |
| Obra CtoLocal-first MCP that scores your codebase's build readiness. Your code never leaves your machine. | Local · stdio |
| Obscura MCPMCP server adapter for Obscura Rust headless browser — web scraping with anti-detection. | Local · stdio |
| Obsd LaunchpadMCP server for AI agents to deploy tokens on Base. One command launch, earn OBSD forever. | Local · stdio |