Skip to content

A2A Agent Card substitution

A2A discovery response edit route authority 30–40 minutes

A gateway discovers a specialist from a real Agent Card. The exercise tests whether changing an advertised interface redirects the next A2A exchange.

Recipe Value
Pause Agent Card response
Attack replace supportedInterfaces[0].url with the shadow endpoint
Control change only description
Receiver proof primary-versus-shadow specialist state
Out-of-band proof routing ledger
Gateway
discovers card
AIT
edits route
Gateway
uses card
Shadow
specialist
Routing
ledger

Start the two receivers

ait lab start --exercise a2a-agent-card-substitution

The exercise starts a primary specialist and a controlled shadow specialist. The Lab drawer displays the shadow endpoint. Copy it from there; do not invent a port or reuse an endpoint from an earlier run.

Run the route substitution

  1. Trigger discovery traffic.
  2. Select the Agent Card response, not the later SendMessage request.
  3. Locate supportedInterfaces[0].url.
  4. Replace it with the displayed shadow endpoint.
  5. Mark the message as the attack arm and forward it.
  6. Allow the gateway's follow-up A2A request to proceed.
  7. Compare primary state, shadow state, and the routing ledger.

The security-relevant event happens after the edited response: the client must consume the card and use the new endpoint. Keep both messages in the evidence chain.

Run the close control

Trigger a new discovery in the same session. Change only the Agent Card description and leave the interface URL untouched. Forward the response and observe where the follow-up request lands.

Artifact Expected attack arm Expected control arm
delivered card shadow URL primary URL, altered description
primary specialist state unchanged receives follow-up request
shadow specialist state receives follow-up request unchanged
routing ledger shadow destination primary destination

Common mistakes

  • Stopping at the diff. A changed card does not prove the gateway used it.
  • Editing the later request. That tests direct redirection, not discovery authority.
  • Losing the shadow receipt. Without a controlled receiver observation, you know routing changed only if the primary remained quiet, not where it went.
  • Reusing stale endpoints. A new lab run may own different loopback ports.

Evidence boundary

The routing ledger proves controlled redirection in this topology. It does not show credential exposure unless the shadow receipt actually contains a scoped, authorized test credential, and the lab does not seed production credentials. On a real target, decide in advance which fields the shadow is permitted to retain and redact exports accordingly.

Done when

You can join the discovery response, its exact URL diff, the follow-up request, primary-versus-shadow state, and the routing ledger into one causal timeline.

Next: Callback substitution and replay moves from request routing to asynchronous delivery configuration.