[ 
https://issues.apache.org/jira/browse/CAMEL-24220?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Andrea Cosentino reassigned CAMEL-24220:
----------------------------------------

    Assignee: Andrea Cosentino

> Camel JBang MCP Server - Add camel_security_scan tool for route security 
> analysis
> ---------------------------------------------------------------------------------
>
>                 Key: CAMEL-24220
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24220
>             Project: Camel
>          Issue Type: Improvement
>          Components: camel-jbang
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>
> Add a new MCP tool that scans a Camel route for security anti-patterns. 
> Distinct from the existing camel_route_harden_context (which focuses on CVE 
> advisories), this tool performs static analysis of route definitions.
> Scope:
> - New tool: camel_security_scan
> - Detect: exposed secrets in route URIs, missing Camel* header filters on 
> consumers, insecure defaults (trustAllCertificates, 
> allowJavaSerializedObject), missing TLS configuration, ObjectInputStream 
> usage without ObjectInputFilter
> - Input: route file path or inline YAML/Java DSL
> - Output: list of findings with severity, file/line location, and remediation 
> guidance
> - Reference Camel security model (design/security.adoc) for rule definitions
> Location: dsl/camel-jbang/camel-jbang-mcp/



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to