Hardens Model Context Protocol (MCP) server integrations for compliance—OAuth 2.1, PKCE, scoped tool sets, transport security, and patterns for Playwright, Postgres, Slack, and Presidio MCP servers in audit workflows. Trigger when deploying, configuring, or auditing MCP servers for HIPAA, PCI, or SOC 2 agent architectures. Do not use for general IAM reviews without MCP focus (use access-control-identity-audit) or PCI script DOM audits (use pci-dss-script-audit).
التثبيت
التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.
Hardens Model Context Protocol (MCP) server integrations for compliance—OAuth 2.1, PKCE, scoped tool sets, transport security, and patterns for Playwright, Postgres, Slack, and Presidio MCP servers in audit workflows. Trigger when deploying, configuring, or auditing MCP servers for HIPAA, PCI, or SOC 2 agent architectures. Do not use for general IAM reviews without MCP focus (use access-control-identity-audit) or PCI script DOM audits (use pci-dss-script-audit).
MCP Compliance Integration
Overview
This skill secures Model Context Protocol (MCP) integrations used by the compliance agent. MCP servers expose tools (Playwright browser automation, Postgres queries, Slack notifications, Presidio DLP) to the agent runtime. Misconfiguration creates pathways for ePHI exfiltration, unauthorized CDE access, and unlogged actions.
Security baseline:
OAuth 2.1 with PKCE for user-delegated MCP access
Tool allowlists—principle of least functionality
TLS 1.2+ for all MCP transport
Structured audit logging without cleartext PHI (see audit-logging-integrity)
BAA coverage for MCP operators processing ePHI (see hipaa-baa-vendor-assessment)
When to Use
Use this skill when:
Deploying new MCP servers for compliance workflows