Back to skill

Security audit

mcp-http-auth-fallback-diagnosis

Security checks for vulnerabilities and agentic risk

Overview

This skill is a focused diagnostic checklist for MCP HTTP authentication issues and explicitly warns against exposing credential values.

Install only if you want help diagnosing MCP HTTP authentication failures. The skill may guide an agent to test configured endpoints and compare credential behavior, so ensure it is used only with servers and credentials you are authorized to troubleshoot, and continue avoiding token values in logs or chat output.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.