hackwither_

reap / rules / transport posture

Agent endpoint served over plaintext HTTP

transport-plaintext ASI07 Insecure Inter-Agent Communication severity: medium

What it detects

Endpoint served over plaintext HTTP. ASI07.

Flags when the target URL itself uses http:// rather than https://.

applies to any agent endpoint over HTTP

Why it matters

Agent traffic, tool arguments, and bearer tokens readable on the wire: insecure communication on the agent's own channel.

OWASP ASI mapping rationale

Example finding

MEDIUM  transport-plaintext   CONFIDENCE
Agent endpoint served over plaintext HTTP
Target URL uses http:// rather than https://. Tool calls, arguments, and any auth tokens are visible to on-path observers.

from a scan of reap-range, bad target

Fix

Serve agent endpoints over TLS only; redirect or refuse plaintext connections.

On reap-range

insecure targetevery target (see limitation below) · Medium
correct target—

Run only this check

reap -t https://your-host/mcp --authorized --include transport-plaintext

Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.