reap / rules / transport posture
No standard rate-limit headers observed
http-rate-limit-absence ASI08 Cascading Failures severity: info
What it detects
Missing standard rate-limit headers (Retry-After, RateLimit-*). ASI08.
Checks initialize/tools/list responses for standard rate-limit headers (Retry-After, RateLimit-*); flags their absence as a DoS reconnaissance signal.
applies to any agent endpoint over HTTP
Why it matters
No advertised limiting means a caller can drive the agent (and everything downstream of it) without backpressure: a cascading-failure concern.
Example finding
LOW http-rate-limit-absence CONFIDENCE No standard rate-limit headers observed The endpoint answered requests but sent no standard rate-limit response headers. This is a reconnaissance signal that the service may not be advertising rate limiting to clients; it is not proof that no limiting exists.
from a scan of reap-range, bad target
Fix
Expose standard rate-limit headers such as Retry-After, RateLimit-Remaining, and RateLimit-Limit, or document the expected client behavior when limits are reached.
On reap-range
| insecure target | bad/mcp (no headers on either verb) · Low |
| correct target | good/mcp sends Retry-After |
Run only this check
reap -t https://your-host/mcp --authorized --include http-rate-limit-absence
Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.