Skip to content

A2A protocol security: see what your agents tell each other.

A2A protocol security covers the messages AI agents exchange over the Agent-to-Agent protocol: tasks, delegations and the replies that come back. The attacks are instructions smuggled into a session, delegations replayed after they should have expired, and trust that grows as it passes down a chain of agents. Cyron AI Security detects all three on your own servers.

What is A2A, and how is it different from MCP?

MCP connects an agent to tools. A2A connects an agent to another agent, which makes its own decisions; that is why trust and delegation matter more in A2A.

Three attacks on agent-to-agent traffic

Each of these attacks arrives as a valid message from an authenticated agent. Each falls under ASI07, insecure inter-agent communication, in the OWASP Top 10 for Agentic Applications (2026).

A2A session smuggling

In A2A session smuggling, a remote agent, malicious or compromised, injects extra turns or instructions into a running agent-to-agent session. The receiving agent acts on them, because they arrive inside a conversation it already trusts. On the wire, the session and task identifiers are valid. The replies carry more than an answer: turns nobody asked for, requests for data the task never needed, or instructions addressed to the receiving agent. Its OWASP class is ASI07.

A2A delegation replay

A delegation hands a task from one agent to another, together with the authority to act on it. In a replay, the attacker captures a delegation or its token and presents it again, after the task has closed or from a different session. On the wire, the same delegation or token appears more than once, long after it was issued or from a caller that never received it. Tokens that never expire make it easy. Its OWASP class is ASI07.

A2A transitive trust

Agent A trusts agent B, and agent B trusts agent C. In a transitive-trust attack, a request from C, or from anything C talks to, inherits A's authority although A never granted it. On the wire, a request several hops down the chain carries more authority than the original caller held, and the scope widens at each hop. Its OWASP class is ASI07.

For research on attacks between agents, see A2ABreak (arXiv, September 2026).

How Cyron AI Security detects them

Cyron AI Security inspects A2A over JSON-RPC: the messages, tasks and delegations that pass between agents. One detector covers each attack, and every finding carries its class from the OWASP Top 10 for Agentic Applications (2026).

Two more detectors watch the identities agents act under. Shared-credential hijack catches one credential used across identities. Confused deputy catches an agent used beyond its caller's authority. Both are classified ASI03. Messages crafted to confuse parsers are refused or flagged.

Detection is deterministic: the same exchange always gets the same verdict, and every verdict can be explained. Inside Cyron On-Premise, A2A findings arrive as Agent Communication Abuse incidents, in the same dashboard and the same SIEM feed as your API incidents.

Cyron AI Security runs self hosted, on a Linux host with a container runtime inside your network. It needs no GPU and never calls home. It runs on prem in your own data centre, or in an air gapped network with no internet at all. For the full set of 15 detectors and a verified blocking result, read Introducing Cyron AI Security.

Detector What it catches Standard
A2A session smuggling Instructions injected into an agent-to-agent session ASI07
A2A delegation replay Replayed delegations and tokens that never expire ASI07
A2A transitive trust Trust escalated through a chain of agents ASI07

What is the A2A protocol?

A2A is an open protocol that lets AI agents built by different teams discover each other, exchange messages and hand tasks to one another.

The A2A specification defines it, and the protocol has reached version 1.0.

How is A2A different from MCP?

MCP connects an agent to tools. A2A connects an agent to other agents. An agent that uses both can be attacked through either, which is why Cyron AI Security protects both.

Can Cyron block an A2A attack?

Yes. You choose the threat classes to block and the severity at which blocking starts. Everything else is allowed and recorded, and blocked calls leave evidence too.

Run Cyron AI Security as a gateway in front of your A2A servers, and it refuses a malicious call before it reaches your agent. Or run it inside Cyron On-Premise, where iris, the eBPF kernel agent, captures agent traffic, your agents need no changes, and the source is blocked at the kernel.

Evaluate it against your own agents

Cyron AI Security installs on a Linux host inside your network. Tell us which MCP servers and agents you run, and we will set up an evaluation on your servers.