reap / rules / recon: capability surface
MCP tool listing accessible without authentication
mcp-unauth-tools-list ASI02 Tool Misuse and Exploitation ASI03 Identity and Privilege Abuse severity: high
What it detects
tools/list answering an unauthenticated caller. ASI02, ASI03. Severity escalates when a returned tool name matches high-risk hints (exec, shell, sql, fetch_url, ...).
Re-issues tools/list with no auth header; flags a successful (200, no RPC error) response, escalating severity if any returned tool name matches high-risk hints (exec, shell, sql, fetch_url, ...).
applies to MCP endpoints
Why it matters
An anonymous caller learning the full tool inventory is the reconnaissance step for tool misuse (ASI02), and it means the endpoint applies no caller identity (ASI03).
Example finding
HIGH mcp-unauth-tools-list HIGH CONFIDENCE MCP tool listing accessible without authentication tools/list returned 3 tool(s) to an unauthenticated caller: exec_shell, search_tools, run_tool Evidence POST /mcp → 200
from a scan of reap-range, bad target
Fix
Require authentication before tools/list, or scope the response so anonymous callers see nothing.
On reap-range
| insecure target | bad/mcp · High (exec_shell) |
| correct target | good/mcp gates tools/list behind auth |
Run only this check
reap -t https://your-host/mcp --authorized --include mcp-unauth-tools-list
Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.