reap / rules / recon: capability surface
MCP enumeration auth posture: open, auth-gated or unreachable
mcp-auth-posture
What it detects
Whether enumeration is open, auth-gated, or unreachable. Emits mcp-enumeration-blocked when gated. Deliberately uncited against an ASI category — records a fact about the endpoint, not a weakness.
Records whether enumeration is open, auth-gated, or unreachable. Deliberately uncited — a fact about the endpoint, not a weakness.
applies to MCP endpoints
Why it matters
Deliberately uncited. It records a fact about the endpoint; it is not a weakness.
On reap-range
| insecure target | bad/mcp → open |
| correct target | good/mcp and bad/mcp/gated → auth-gated |
Run only this check
reap -t https://your-host/mcp --authorized --include mcp-auth-posture
Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.