reap / rules / auth and session posture
MCP session ID entropy looks weak or predictable
mcp-session-id-entropy ASI03 Identity and Privilege Abuse severity: medium
What it detects
Weak or predictable session identifiers — the value itself is never recorded in the finding. ASI03. Streamable-HTTP only.
Analyzes the Mcp-Session-Id header value for short length, small character set, repeated characters, or low estimated bit-entropy. Streamable-HTTP only.
applies to MCP endpoints
Why it matters
A guessable session ID lets an attacker assume another caller's identity directly.
Example finding
MEDIUM mcp-session-id-entropy HIGH CONFIDENCE MCP session ID entropy looks weak or predictable The MCP session ID returned by the server appears to have low entropy or a predictable format: session ID is shorter than 16 characters, estimated entropy is low (36 bits)
from a scan of reap-range, bad target
Fix
Use a cryptographically random, high-entropy session identifier for MCP sessions and avoid sequential or human-readable formats.
On reap-range
| insecure target | bad/mcp · Medium (sess001) |
| correct target | good/mcp sends a secrets.token_urlsafe(32) ID |
Run only this check
reap -t https://your-host/mcp --authorized --include mcp-session-id-entropy
Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.