
Elicitation Auditor
io.github.4hmetuyarv0.1.1Updated Sep 30, 2026
MCP elicitation anti-patterns: secrets in forms, third-party authorize URLs, credentials in URLs
Installation
In SourceWeft
- Open Elicitation Auditor in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
@guardbee/mcp-elicitation-auditor
π¬π§ English | πΉπ· TΓΌrkΓ§e
An MCP server that scans MCP server source for elicitation anti-patterns in the 2026-07-28 specification.
That revision deprecated sampling and roots. Elicitation is the remaining way a server asks the client for something. Form mode collects structured data through the client. URL mode sends the user to a page the client must not read. The spec draws a hard line between them.
This package sends usage telemetry by default (tool name + short parameters, scanned code is never included β see
@guardbee/mcp-telemetry). Disable withGUARDBEE_TELEMETRY=0.
What it flags
- Form-mode secrets.
elicitInput/ctx.elicit/elicitation/createwith mode omitted orform, whose schema asks forpassword,apiKey,access_token,cvv, and the same family. A name and email form is allowed by the spec and is not flagged.secretQuestionis not treated assecret. - Direct third-party authorize. URL mode whose
urlpath containsauthorize,oauth, oroauth2, unless the path goes through your own/connectroute. That is the forwarded-link phishing case in the spec: the user who opens the link must be checked against the MCP user before any redirect. - Credential or personal data in the URL. Query keys such as
access_token,code, oremail. The URL is shown to the MCP client. - Cleartext HTTP, except
localhostand127.0.0.1. - Clickable URL in a form. A form message or field description that contains an
httplink. The spec says that link belongs in URL mode. - Form answer used as identity. The submitted email or username is passed to
findUser,loginAs, or assigned toreq.user, with no comparison to the tokensubclaim. - Ignored decline/cancel. Code reads
.contentand never looks at.action,decline, orcancel. Checkingaction !== "accept"is enough. Sending the email as a notification address is not treated as an identity check.
Tools
CLI
guardbee.yml:
No API key. Static analysis only.
Source: packages/elicitation-auditor/README.md at commit 4c36e56
Tools
0Version history
1- v0.1.1LatestSep 30, 2026
