Skip to main content

AGENTFORCE-AF-09: Unauthenticated MCP / A2A Agent Endpoint

๐Ÿ”ด High ยท MuleSoft Agent Fabric

Detects Mule MCP servers and A2A servers, and Agent Fabric broker interfaces, that accept calls with no authentication visible in the repository (no API autodiscovery / API Manager policy, no security filter, no A2A task authorizer, no inbound broker policy). Critical when CORS allows any origin and the endpoint writes.

Detailsโ€‹

FieldValue
Rule IDAGENTFORCE-AF-09
SeverityHigh
CategoryMuleSoft Agent Fabric

Remediationโ€‹

Protect the endpoint: add <api-gateway:autodiscovery> and apply a client-id, JWT or OAuth 2.0 policy in API Manager (or put it behind Flex Gateway), add an <a2a:task-authorizer-listener> flow for A2A servers, bind an authentication policy to brokers.<id>.interfaces.a2a.policies.inbound, and replace <http:public-resource/> CORS with an explicit origin list.

See Alsoโ€‹