reap / rules / recon: capability surface
Tool enumeration blocked by authentication
mcp-enumeration-blocked ASI09 Human-Agent Trust Exploitation severity: info
What it detects
Companion to mcp-tool-capability-surface: reports informationally when tools/list is correctly gated behind auth. Uncited — a clean-pass signal, not a finding.
Companion finding to mcp-tool-capability-surface: reports (informationally) when tools/list is correctly gated behind auth (401/403), so enumeration coverage is documented either way. Deliberately uncited against an ASI category — it records a fact, not a weakness.
applies to MCP endpoints
Why it matters
Deliberately uncited. It records a fact about the endpoint; it is not a weakness.
Example finding
INFO mcp-enumeration-blocked HIGH CONFIDENCE Tool enumeration blocked by authentication tools/list returned 401 without credentials — the server correctly gates enumeration behind authentication, so no tool inventory is available from this vantage point. Evidence POST /mcp/gated → 401
from a scan of reap-range, gated target
On reap-range
| insecure target | bad/mcp/gated, good/mcp (401 on tools/list) · Info |
| correct target | expected; records that enumeration was refused rather than unreachable |
Run only this check
reap -t https://your-host/mcp --authorized --include mcp-auth-posture
mcp-enumeration-blocked is reported by the mcp-auth-posture probe, so include that.
Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.