Skip to main content

AGENTFORCE-22.1: Unsafe Autonomous HTTP Callouts

๐Ÿšจ Critical ยท SSRF

Detects Apex classes invoked by agent actions that make HTTP callouts to dynamically-constructed endpoints without Named Credential enforcement. This enables SSRF: a prompt injection attack can redirect the agent's HTTP callout to an attacker-controlled server or internal network resource.

Detailsโ€‹

FieldValue
Rule IDAGENTFORCE-22.1
SeverityCritical
CategorySSRF
ComplianceSOC2_CC7, OWASP_MCP_TOP_10

Remediationโ€‹

Refer to the SquireX documentation for remediation guidance specific to AGENTFORCE-22.1.

See Alsoโ€‹