Various exploits for MCP clients that are capable of the OAuth spec. These will all launch a calculator on Windows but the MCP inspector one can be adapted for other platforms.
For the exploit against cmd.exe.
npm install -g @anthropic-ai/claude-code@1.0.53
npm install -g @anthropic-ai/claude-code@1.0.57
npm install -g @google/gemini-cli@0.1.14
npx @modelcontextprotocol/inspector@0.16.3