AGENTFORCE-AF-06: Agent Fabric Broker Write Tool Without Approval
๐ด High ยท MuleSoft Agent Fabric
Detects Agent Fabric brokers whose LLM can call a state-changing MCP tool or A2A agent (create/update/delete in Salesforce, Workday, a database, Jira, ServiceNow, SAP, โฆ) with no human approval step. Severity is high, critical when the write is a delete or hits a database or Workday, and one level lower when the write is only inferred from a tool name or card skill or the broker has an INPUT_REQUIRED step elsewhere.
Detailsโ
| Field | Value |
|---|---|
| Rule ID | AGENTFORCE-AF-06 |
| Severity | High |
| Category | MuleSoft Agent Fabric |
Remediationโ
Take the write out of the LLM's choice: remove it from reasoning.actions and call it from a deterministic executor (run @actions.<name>) that is reached only after approval: a subagent asks the user, an echo node returns TASK_STATE_INPUT_REQUIRED, and a router continues to the executor when the user approves. If the tool must stay LLM-callable, make the Mule flow itself require approval (create a pending request instead of writing) or limit it to read operations.