hackwither_

reap / rules / transport posture

No standard rate-limit headers observed

http-rate-limit-absence ASI08 Cascading Failures severity: info

What it detects

Missing standard rate-limit headers (Retry-After, RateLimit-*). ASI08.

Checks initialize/tools/list responses for standard rate-limit headers (Retry-After, RateLimit-*); flags their absence as a DoS reconnaissance signal.

applies to any agent endpoint over HTTP

Why it matters

No advertised limiting means a caller can drive the agent (and everything downstream of it) without backpressure: a cascading-failure concern.

OWASP ASI mapping rationale

Example finding

LOW  http-rate-limit-absence   CONFIDENCE
No standard rate-limit headers observed
The endpoint answered requests but sent no standard rate-limit response headers. This is a reconnaissance signal that the service may not be advertising rate limiting to clients; it is not proof that no limiting exists.

from a scan of reap-range, bad target

Fix

Expose standard rate-limit headers such as Retry-After, RateLimit-Remaining, and RateLimit-Limit, or document the expected client behavior when limits are reached.

On reap-range

insecure targetbad/mcp (no headers on either verb) · Low
correct targetgood/mcp sends Retry-After

Run only this check

reap -t https://your-host/mcp --authorized --include http-rate-limit-absence

Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.