reap / rules / auth and session posture
OAuth redirect URI registration appears overly broad
mcp-redirect-uri-laxity ASI03 Identity and Privilege Abuse severity: medium
What it detects
Overly broad or wildcard OAuth redirect URI registration. ASI03.
Scans discovered OAuth metadata for registered redirect URIs that are wildcarded, non-HTTPS, missing a host, or missing a path.
applies to MCP endpoints
Why it matters
Broad redirect registration enables confused-deputy and code-interception attacks against the agent's identity.
Example finding
MEDIUM mcp-redirect-uri-laxity MEDIUM CONFIDENCE OAuth redirect URI registration appears overly broad The discovered OAuth metadata includes redirect URIs that are broad or wildcarded, which increases the risk of confused-deputy or open redirect abuse. Evidence GET /.well-known/oauth-authorization-server → 200
from a scan of reap-range, bad target
Fix
Restrict registered redirect URIs to exact allowed origins and paths, and avoid wildcards or overly permissive URL patterns.
On reap-range
| insecure target | bad host well-known (https://evil.example/*) · Medium |
| correct target | good host well-known has an exact scoped URI |
Run only this check
reap -t https://your-host/mcp --authorized --include mcp-redirect-uri-laxity
Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.