File: packages/agent/src/routes/squad-api.ts + index.ts:92
POST /api/squad/kill toggles kill switch without any auth. Mounted without verifyJwt. Any unauthenticated user can pause all vault operations.
Fix: Add verifyJwt middleware + admin role check.
Ref: PR #70 audit
File:
packages/agent/src/routes/squad-api.ts+index.ts:92POST /api/squad/killtoggles kill switch without any auth. Mounted withoutverifyJwt. Any unauthenticated user can pause all vault operations.Fix: Add
verifyJwtmiddleware + admin role check.Ref: PR #70 audit