Skip to content

[REVIEW] zero-trust-assessment: add private app connector fail-open gates #2744

@stmr

Description

@stmr

[REVIEW] zero-trust-assessment: add private app connector fail-open gates

Skill Being Reviewed

Skill name: zero-trust-assessment
Skill path: skills/identity/zero-trust-assessment/

False Positive Analysis

A private app connector outage is acceptable if traffic fails closed, users see controlled denial, and emergency bypass requires approval plus logging.

Coverage Gaps

The skill should test private-access connector failure modes. Some ZTNA designs silently route around connectors, fall back to VPN, or leave internal apps reachable from trusted networks.

Edge Cases

  • Connector health check passes while policy sync fails.
  • Split DNS exposes direct private address.
  • Emergency bypass persists after outage.

Remediation Quality

  • Add fail-open test: disable connector, revoke policy sync, test direct route, test DNS, and record outcome.
  • Require bypass owner, expiry, and audit trail.
  • Flag private apps reachable without policy enforcement.

Comparison to Other Tools

ZTNA consoles show connector status; network tests prove enforcement behavior.

Overall Assessment

Add private connector fail-open gates so zero-trust access does not degrade into implicit trust.

Bounty Info

  • I have read and agree to the CONTRIBUTING.md bounty terms.
  • Preferred payment method: PayPal samik4184@gmail.com

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions