reap / rules / transport posture
Agent endpoint served over plaintext HTTP
transport-plaintext ASI07 Insecure Inter-Agent Communication severity: medium
What it detects
Endpoint served over plaintext HTTP. ASI07.
Flags when the target URL itself uses http:// rather than https://.
applies to any agent endpoint over HTTP
Why it matters
Agent traffic, tool arguments, and bearer tokens readable on the wire: insecure communication on the agent's own channel.
Example finding
MEDIUM transport-plaintext CONFIDENCE Agent endpoint served over plaintext HTTP Target URL uses http:// rather than https://. Tool calls, arguments, and any auth tokens are visible to on-path observers.
from a scan of reap-range, bad target
Fix
Serve agent endpoints over TLS only; redirect or refuse plaintext connections.
On reap-range
| insecure target | every target (see limitation below) · Medium |
| correct target | — |
Run only this check
reap -t https://your-host/mcp --authorized --include transport-plaintext
Not installed? Install REAP. Only scan systems you own or are authorised to test. Reference: docs/PROBES.md.