AG-024
Destructive Tool Authentication Disabled
medium
Page text and source link for your AI assistant. Nothing is sent automatically.
What Foo Guard detects
A tool explicitly declares destructive behavior and disables tool authentication. This configuration concern does not establish public exposure or rule out a host or Gateway authentication boundary.
When this rule triggers
The rule triggers when The same tool has destructive === true and requiresAuth === false. Both must be explicit booleans; names, descriptions, and missing values do not trigger this rule.
Foo Guard evaluates the normalized configuration supplied to the scanner. A finding describes configuration risk; it does not establish that an attack occurred. An absent finding does not prove that an undeclared capability is safe.
How to fix
Require authentication and least-privilege authorization before destructive execution. Verify and document any equivalent external boundary before recording a scoped exception.
Verify who can invoke the destructive operation and where authentication and authorization are enforced. For a local or externally authenticated tool, validate that boundary and record a scoped exception if appropriate. The scan does not test network exposure. Changing metadata alone does not secure execution.
Verify the change
Update the actual agent configuration and the underlying permissions or controls, then run the scanner again. Inspect the finding’s evidence path to confirm the intended setting changed. Do not clear a finding by changing a declaration that no longer reflects the deployed agent.
Test the affected workflow in an isolated environment, including an operation that should be denied. Keep related findings in view: fixing this rule does not automatically resolve other identity, permission, tool, or audit risks.