hackwither_

reap / rules / recon: capability surface

MCP tool listing accessible without authentication

mcp-unauth-tools-list ASI02 Tool Misuse and Exploitation ASI03 Identity and Privilege Abuse severity: high

What it detects

tools/list answering an unauthenticated caller. ASI02, ASI03. Severity escalates when a returned tool name matches high-risk hints (exec, shell, sql, fetch_url, ...).

Re-issues tools/list with no auth header; flags a successful (200, no RPC error) response, escalating severity if any returned tool name matches high-risk hints (exec, shell, sql, fetch_url, ...).

applies to MCP endpoints

Why it matters

An anonymous caller learning the full tool inventory is the reconnaissance step for tool misuse (ASI02), and it means the endpoint applies no caller identity (ASI03).

OWASP ASI mapping rationale

Example finding

HIGH  mcp-unauth-tools-list  HIGH CONFIDENCE
MCP tool listing accessible without authentication
tools/list returned 3 tool(s) to an unauthenticated caller: exec_shell, search_tools, run_tool
Evidence  POST /mcp → 200

from a scan of reap-range, bad target

Fix

Require authentication before tools/list, or scope the response so anonymous callers see nothing.

On reap-range

insecure targetbad/mcp · High (exec_shell)
correct targetgood/mcp gates tools/list behind auth

Run only this check

reap -t https://your-host/mcp --authorized --include mcp-unauth-tools-list

Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.