Skip to main content

AGENTFORCE-MCP-01: Token Passthrough Exposure Configuration

๐Ÿšจ Critical ยท Headless MCP Access

Detects MCP server configurations using static OAuth client IDs without PKCE enforcement, missing Device Authorization Grant patterns, or lacking Flex Gateway routing policies. Prevents token passthrough attacks where session credentials are exposed to external agents.

Detailsโ€‹

FieldValue
Rule IDAGENTFORCE-MCP-01
SeverityCritical
CategoryHeadless MCP Access

Remediationโ€‹

Refer to the SquireX documentation for remediation guidance specific to AGENTFORCE-MCP-01.

See Alsoโ€‹