AGENTFORCE-AF-09: Unauthenticated MCP / A2A Agent Endpoint
๐ด High ยท MuleSoft Agent Fabric
Detects Mule MCP servers and A2A servers, and Agent Fabric broker interfaces, that accept calls with no authentication visible in the repository (no API autodiscovery / API Manager policy, no security filter, no A2A task authorizer, no inbound broker policy). Critical when CORS allows any origin and the endpoint writes.
Detailsโ
| Field | Value |
|---|---|
| Rule ID | AGENTFORCE-AF-09 |
| Severity | High |
| Category | MuleSoft Agent Fabric |
Remediationโ
Protect the endpoint: add <api-gateway:autodiscovery> and apply a client-id, JWT or OAuth 2.0 policy in API Manager (or put it behind Flex Gateway), add an <a2a:task-authorizer-listener> flow for A2A servers, bind an authentication policy to brokers.<id>.interfaces.a2a.policies.inbound, and replace <http:public-resource/> CORS with an explicit origin list.