Versatile AI Risk Assessment

AI threat catalogueAgentic and Autonomous AIProduction

Insecure Inter-Agent Communication (A2A/MCP)

In multi-agent systems, agents exchange messages and discover tools through shared registries, for example via the A2A or MCP protocol. Without reliable mutual authentication, an attacker can impersonate a legitimate agent.

As of: July 2026 · Catalogue version 2026.07.17.3 · 4 mitigations · 6 verified sources

Description

Agent-to-agent protocols such as A2A (Agent2Agent) and MCP (Model Context Protocol) let agents delegate tasks to other agents and discover tools through shared registries. Many implementations rely on weak or missing mutual authentication. An attacker can register an agent with a similar name or capability description, intercept messages, or impersonate the intended recipient toward a delegating agent. The delegating agent effectively transfers its own rights to the impersonating participant.

Possible impact

An impersonating agent can take over delegated tasks, return manipulated results, or exfiltrate intercepted data, all with the privileges of the system that trusted it. In interconnected multi-agent architectures, a single compromised participant can affect multiple workflows. The EU AI Act requires resilience against third-party manipulation attempts and effective risk management.

Example

A research agent delegates a subtask to a data-retrieval agent via a shared registry. An attacker registers a malicious agent there with a near-identical name and matching capability description. The selection logic picks the malicious agent instead of the legitimate one. It returns manipulated data or forwards the query, including sensitive details, to an external server.

Recommended mitigations (4)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

OWASP LLM Top 10 ASI07:2026MITRE ATLAS AML.T0073 · AML.T0110EU AI Act Article 15(5) · Article 9(1), 9(2)(a), 9(2)(d)GDPR Article 32(1)(b)

Verified references (6)

Every reference states the framework, the exact location and the publishing organisation.

  • OWASP LLM Top 10 ASI07:2026 Insecure Inter-Agent CommunicationASI07 Insecure Inter-Agent Communication, pp. 27–29 of the official PDF OWASP FoundationOriginal
  • MITRE ATLAS AML.T0073 ImpersonationATLAS.yaml technique object with id AML.T0073 (pinned release v5.6.0) MITREOriginal
  • MITRE ATLAS AML.T0110 AI Agent Tool PoisoningATLAS.yaml technique object with id AML.T0110 (pinned release v5.6.0) MITREOriginal
  • EU AI Act Article 15(5) Accuracy, robustness and cybersecurityArticle 15(5), including the express references to data/model poisoning, adversarial examples/evasion, confidentiality attacks and model flaws European Union (EUR-Lex)Original
  • EU AI Act Article 9(1), 9(2)(a), 9(2)(d) Risk management systemArticle 9(1), 9(2)(a), 9(2)(d), read with Article 9(3) European Union (EUR-Lex)Original
  • GDPR Article 32(1)(b) Security of processingArticle 32(1)(b), read with Article 32(1) and 32(2) European Union (EUR-Lex)Original

Terms on this page

Glossary terms that occur in this entry. Every link leads to the full explanation.

More entries from the topic group Agentic and Autonomous AI.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“Insecure Inter-Agent Communication (A2A/MCP)”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/insecure-inter-agent-communication/

← Back to the full catalogue