Skip to main content

AGENTFORCE-AF-06: Agent Fabric Broker Write Tool Without Approval

๐Ÿ”ด High ยท MuleSoft Agent Fabric

Detects Agent Fabric brokers whose LLM can call a state-changing MCP tool or A2A agent (create/update/delete in Salesforce, Workday, a database, Jira, ServiceNow, SAP, โ€ฆ) with no human approval step. Severity is high, critical when the write is a delete or hits a database or Workday, and one level lower when the write is only inferred from a tool name or card skill or the broker has an INPUT_REQUIRED step elsewhere.

Detailsโ€‹

FieldValue
Rule IDAGENTFORCE-AF-06
SeverityHigh
CategoryMuleSoft Agent Fabric

Remediationโ€‹

Take the write out of the LLM's choice: remove it from reasoning.actions and call it from a deterministic executor (run @actions.<name>) that is reached only after approval: a subagent asks the user, an echo node returns TASK_STATE_INPUT_REQUIRED, and a router continues to the executor when the user approves. If the tool must stay LLM-callable, make the Mule flow itself require approval (create a pending request instead of writing) or limit it to read operations.

See Alsoโ€‹