A2A Agent Card substitution¶
A2A discovery response edit route authority 30–40 minutes
A gateway discovers a specialist from a real Agent Card. The exercise tests whether changing an advertised interface redirects the next A2A exchange.
| Recipe | Value |
|---|---|
| Pause | Agent Card response |
| Attack | replace supportedInterfaces[0].url with the shadow endpoint |
| Control | change only description |
| Receiver proof | primary-versus-shadow specialist state |
| Out-of-band proof | routing ledger |
discovers card AIT
edits route Gateway
uses card Shadow
specialist Routing
ledger
Start the two receivers¶
The exercise starts a primary specialist and a controlled shadow specialist. The Lab drawer displays the shadow endpoint. Copy it from there; do not invent a port or reuse an endpoint from an earlier run.
Run the route substitution¶
- Trigger discovery traffic.
- Select the Agent Card response, not the later
SendMessagerequest. - Locate
supportedInterfaces[0].url. - Replace it with the displayed shadow endpoint.
- Mark the message as the attack arm and forward it.
- Allow the gateway's follow-up A2A request to proceed.
- Compare primary state, shadow state, and the routing ledger.
The security-relevant event happens after the edited response: the client must consume the card and use the new endpoint. Keep both messages in the evidence chain.
Run the close control¶
Trigger a new discovery in the same session. Change only the Agent Card
description and leave the interface URL untouched. Forward the response and
observe where the follow-up request lands.
| Artifact | Expected attack arm | Expected control arm |
|---|---|---|
| delivered card | shadow URL | primary URL, altered description |
| primary specialist state | unchanged | receives follow-up request |
| shadow specialist state | receives follow-up request | unchanged |
| routing ledger | shadow destination | primary destination |
Common mistakes¶
- Stopping at the diff. A changed card does not prove the gateway used it.
- Editing the later request. That tests direct redirection, not discovery authority.
- Losing the shadow receipt. Without a controlled receiver observation, you know routing changed only if the primary remained quiet, not where it went.
- Reusing stale endpoints. A new lab run may own different loopback ports.
Evidence boundary¶
The routing ledger proves controlled redirection in this topology. It does not show credential exposure unless the shadow receipt actually contains a scoped, authorized test credential, and the lab does not seed production credentials. On a real target, decide in advance which fields the shadow is permitted to retain and redact exports accordingly.
Done when¶
You can join the discovery response, its exact URL diff, the follow-up request, primary-versus-shadow state, and the routing ledger into one causal timeline.
Next: Callback substitution and replay moves from request routing to asynchronous delivery configuration.