AGENTFORCE-AF-08: Agent Fabric Connection Without Authentication
๐ด High ยท MuleSoft Agent Fabric
Detects Agent Network connections to A2A agents and MCP servers (context.connections, kind a2a or mcp) with no authentication block and no credential-injecting outbound policy, so the broker calls the agent or tool server anonymously. High for a literal remote URL, medium when the URL is a deploy-time variable, low for loopback.
Detailsโ
| Field | Value |
|---|---|
| Rule ID | AGENTFORCE-AF-08 |
| Severity | High |
| Category | MuleSoft Agent Fabric |
Remediationโ
Add an authentication block to the connection (context.connections.<id>.authentication with kind oauth2-client-credentials, oauth2-obo, apikey-client-credentials or basic, values from ${secure::โฆ} properties), or bind an outbound credential-injection policy to it, and require that authentication on the agent / MCP server itself (API Manager policy or task authorizer).