Skip to main content

Browse the directory

Showing 15 resources for "authorization"
Saved
Active

1 trusted · 12 review · 2 limited in this set — compare to see which signals differ.

Trust snapshot

15 results in this view

Claimed
0%(0/15)

3 trust signals differ in this sample: Package trust, Source provenance, Submitter

Signals differ on Package trust, Source provenance, Submitter — add entries to compare before you install.

Rollout signal scan

2 rollout risk signals in current results

Biggest gaps: metadata review, package integrity. 0 entries have 2+ required gaps.

12 scanned

Install payload

Install payload is broadly covered in current results.

good

100% (12/12)

Adoption queue

Browse adoption queue · balanced

2/15 visible results are in hold tier and need mitigation before adoption.

ready 0caution 13hold 2
caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

commands/mcp-auth-audit · trust review · confidence 67%

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

rules/ai-generated-mass-assignment-review-rules · trust review · confidence 67%

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

rules/laravel-expert · trust review · confidence 67%

MCP Authorization Boundary Review Agent

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

agents/mcp-authorization-boundary-review-agent · trust review · confidence 67%

MCP Authorization Review Stack

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

collections/mcp-authorization-review-stack · trust review · confidence 67%

Decision confidence

Decision confidence scan · balanced

1/15 results are high-confidence for the selected preset.

high 1medium 14low 0

AI-Generated Mass Assignment Review Rules

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

rules/ai-generated-mass-assignment-review-rules · trust review

MCP Authorization Boundary Review Agent

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

agents/mcp-authorization-boundary-review-agent · trust review

MCP Authorization Review Stack

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

collections/mcp-authorization-review-stack · trust review

Freshness distribution

Mostly fresh with a few aging entries

Median age 53 days; 11 fresh, 1 aging or stale of 12 scanned.

median 53d

Aging

91–180 days

8%

1 entry

Stale

> 180 days

0%

0 entries

Theme distribution

Results center on mcp

67% of this view shares the top theme. Leading themes: mcp, security, oauth.

Focused

44 distinct themes across 15 scanned

Expert MCP capability skill for secure server authoring, tool schema discipline, authorization boundaries, and prompt-injection risk review.

Level:expertType:capability-packVerified:validated
Safety ✓ Privacy ✓

Source-backed rules for reviewing AI-generated endpoints and data-access code before merge for insecure direct object reference risk, covering per-request object-level authorization checks, scoped database lookups, identifier exposure, and consistent enforcement across read, write, and admin operations.

Transform Claude into a Laravel specialist with deep knowledge of routing, Eloquent ORM, form requests, policies, queues, and production deployment patterns.

Slash command for auditing a remote MCP server authorization setup, including protected resource metadata, authorization server discovery, OAuth resource indicators, token audience validation, scopes, and token passthrough risk.

Invocation:/mcp-auth-audit <server-url>
Safety ✓ Privacy ✓

Source-backed specialist agent for reviewing remote MCP authorization boundaries, protected resource metadata, resource indicators, token audience validation, token passthrough risk, and least-privilege scopes.

Source-backed collection for reviewing OAuth-backed and remote MCP servers: protected resource metadata, token audience checks, least-privilege scopes, config privacy, local tool access, and interactive server inspection.

Source-backed rules for reviewing remote MCP server authorization boundaries: protected resource metadata, OAuth resource indicators, token audience checks, least-privilege scopes, and cross-server token isolation.

Practical guide for checking MCP protected resource metadata, authorization server discovery, resource indicators, token audience binding, and 401 challenge behavior before trusting a remote MCP server.

PreToolUse hook that blocks edits adding remote MCP server URLs unless their host appears in an explicit allowlist, reducing accidental connection to unreviewed OAuth, SSE, or Streamable HTTP MCP endpoints.

Trigger:PreToolUse
Safety ✓ Privacy ✓

Source-backed rules for reviewing AI-generated code that binds request parameters to model/entity objects before merge for mass assignment risk, covering allowlist field binding, DTOs that exclude sensitive fields, and the framework-specific autobinding features that make this easy to introduce by default.

A source-backed guide for designing Model Context Protocol servers with explicit authorization boundaries, narrow tools, scoped resources, privacy-aware logging, and least-privilege runtime access.

Slash command that reviews a pull request diff for security regressions: authentication and authorization gaps, injection surfaces, secret exposure, unsafe deserialization, and dependency risk introduced by the change.

Invocation:/pr-security-review [pr-number]
Safety ✓ Privacy ✓
Microsoft MCP Gateway logo

MIT-licensed Kubernetes gateway and management layer for MCP servers, with session-aware routing, adapter lifecycle APIs, tool registration, Entra ID role authorization, and optional agent/session preview resources.

Practical checklist for reviewing remote MCP server authorization, resource indicators, bearer-token handling, HTTPS transport, PKCE, and token passthrough risks before connecting an AI client.

A source-backed Model Context Protocol starter collection for SaaS builders: connect product code, database state, payments, deployment telemetry, issue tracking, and production errors while keeping MCP authorization and tool boundaries explicit.