“I started this project on a lark, fully expecting the AI to produce terrible code for me to laugh at.”
Cloudflare had an AI write its OAuth 2.1 library for MCP servers and says every line was checked against the RFCs by security experts. On May 1 the repo published two advisories. One let redirect URIs go unchecked. The other was a downgrade that completely bypassed PKCE.