secure-mcp-server
m00kk/agent-skills-playbook/skills/secure-mcp-server/SKILL.md
Hardens MCP servers with OAuth, scoped tools, input validation, and safe defaults. Use when securing MCP, adding authentication, preventing tool abuse, or reviewing MCP security before production.
Skill0 starsChanged 4 months ago
- Reads credentials
--- name: secure-mcp-server description: >- Hardens MCP servers with OAuth, scoped tools, input validation, and safe defaults. Use when securing MCP, adding authentication, preventing tool abuse, or reviewing MCP security before production. --- # Secure MCP Server ## Threat model (agent context) | Risk | Mitigation | |------|------------| | Prompt injection → tool abuse | Scoped tools, human approval for writes | | Over-broad tools | Split read vs write tools; deny by default | | Credential exfil | Never return env; mask tokens in logs | | SSRF via URL tools | Allowlist hosts; block private IP ranges | ## Workflow 1. **Inventory tools** — classify: read / write / admin / network 2. **Apply least privilege** — remove unused tools; narrow parameters 3. **Auth layer** — remote servers: OAuth 2.1 + PKCE; local: OS user boundary only 4. **Validation** — max length, enum fields, regex for IDs 5. **Audit** — log tool name + args hash (not secrets) ## OAuth pattern (remote HTTP) - Register client with redirect URI - Store refresh tokens server-side only - Pass short-lived access tokens per request scope - Document required scopes in README ## Destructive operations Require one of: - Separate `*_confirm` tool that needs explicit `confirmed: true` - Client-side approval (Cursor user confirms) - Idempotency keys for retried writes ## Review commands Run from repo root (adjust paths): ```bash # Find dangerous patterns rg -n 'subprocess|os\.system|eval\(|exec\(|shell=True' --glob '!node_modules' rg -n 'password|secret|api_key|token' --glob '!.env.example' ``` ## Pass criteria - [ ] No tool returns full filesystem or env - [ ] Network tools use allowlists - [ ] Write tools documented and gated - [ ] Security section in README See build-mcp-server for implementation scaffolding.
Discussion
Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.
Posts are public.Sign in to post
No one has posted yet. Be the first.

