Agent Guide for Apache Synapse

This file is read by automated agents (security scanners, code analyzers, AI assistants) operating on this repository.

Security

Security model: SECURITY.md -> THREAT_MODEL.md

Agents that scan this repository should consult SECURITY.md and the linked THREAT_MODEL.md before reporting issues. Synapse is a mediation engine / ESB: the untrusted message sender is the adversary, while the integration configuration (sequences, scripts, XSLT/XQuery bodies, endpoint addresses) is trusted operator input. The model covers transports, XSLT/XQuery transforms (XXE/SSRF), dynamic endpoint routing (SSRF), and message DoS.