mcp-oauth-onboardinglisted
Install: claude install-skill YosefHayim/dufflebag
# MCP OAuth Onboarding
Complete the whole onboarding path: trustworthy endpoint, correct scope, browser consent, authenticated status, agent discovery, and one harmless real tool call.
## Safety
- Use official provider and agent documentation for current CLI syntax, transport, and OAuth behavior. Do not execute an install command copied from an untrusted page without inspection.
- Inspect existing same-name MCP entries before adding or changing one. Never overwrite or remove a working configuration silently.
- Do not ask the user to paste passwords, authorization codes, client secrets, access tokens, cookies, or bearer tokens into chat.
- OAuth consent belongs to the user. Pause for their browser approval when required; do not claim to approve permissions on their behalf.
- Verify with a read-only list, get, search, or identity operation. Do not create, send, publish, delete, or purchase anything as an onboarding test.
## Workflow
1. Identify the target agent, required scope, MCP name, official endpoint or command, transport, permissions, and expected tools. If “this MCP” is ambiguous, resolve it from repository/config context or ask for the missing trusted source.
2. Check CLI availability and current version, then inspect existing MCP configuration at project, user, and managed scopes. Record conflicts without exposing secret fields.
3. Read the live command help or official docs. Build the exact add command with explicit scope; for global Claude Code availability, use