Skip to main content

AGENTFORCE-15.1: External Service Without Certificate Pinning

๐Ÿ”ด High ยท External Service Security

Detects Named Credentials used for external service calls that lack certificate pinning (useClientCertificate = false). Agents calling external APIs over unpinned connections are vulnerable to Man-in-the-Middle interception of sensitive tool output.

Detailsโ€‹

FieldValue
Rule IDAGENTFORCE-15.1
SeverityHigh
CategoryExternal Service Security
ComplianceSOC2_CC7, OWASP_MCP_TOP_10

Remediationโ€‹

Refer to the SquireX documentation for remediation guidance specific to AGENTFORCE-15.1.

See Alsoโ€‹