Skip to main content

AGENTFORCE-33.1: MCP Over-Provisioning

๐Ÿ”ด High ยท Graph: MCP Identity Mismatch

[Enterprise] Detects MCP server configurations where the authorizing Connected App has full-scope OAuth access (full/api/chatter_api) disproportionate to the MCP tool's stated narrow purpose. The integration identity has more power than the tool requires.

Detailsโ€‹

FieldValue
Rule IDAGENTFORCE-33.1
SeverityHigh
CategoryGraph: MCP Identity Mismatch
ComplianceOWASP_MCP_TOP_10, SOC2_CC6

Remediationโ€‹

Refer to the SquireX documentation for remediation guidance specific to AGENTFORCE-33.1.

See Alsoโ€‹