Skip to content

Delegated A2A message

A2A request sender → receiver value authority 20–30 minutes

A gateway delegates a controlled approval to a specialist. The exercise asks a precise question: can a value change after the sender creates the request but before the receiver acts on it?

Recipe Value
Pause message/send request
Attack amount 25 → 75
Control change only human-readable message text
Receiver proof specialist state
Out-of-band proof approval effect ledger
Gateway
amount 25
AIT
edit request
Specialist
reads amount
MCP
policy
Ledger
records action

Start the target

ait lab start --exercise delegated-a2a-message

In the Lab drawer, select Send exercise traffic. One pending A2A request should appear. Confirm its operation is message/send and its direction is from gateway to specialist before editing anything.

Run the attack arm

  1. Open the pending request in the structured editor.
  2. Find /params/message/metadata/amount; its baseline value is 25.
  3. Set the arm to attack.
  4. Change the value to 75 and inspect the diff.
  5. Select Forward modified.
  6. Open receiver state and the effect ledger in the Lab drawer.

The specialist state proves the receiver parsed the delivered amount. The approval ledger proves the controlled receiver acted with that amount. A modified request in the traffic timeline proves neither on its own.

Run the close control

Trigger the same exercise again without resetting the session. Change only the human-readable text in the message and leave metadata.amount at 25. Mark this message as the control arm and forward it.

The control crosses the same process and protocol boundary, is visible to the same receiver, and differs from the attack in the authority-bearing field. If it moves the recorded amount too, the result is not isolated to amount authority.

Read the evidence

Observation What it establishes What it does not establish
edited request in AIT the mutation was formed that the receiver accepted it
specialist state shows 75 the receiver processed the mutation that an action occurred
approval ledger shows 75 the controlled action used the delivered value behavior on another target
text-only control remains 25 the tested field, not any edit, explains the change a general A2A vulnerability

Use status when you want the same evidence in the terminal:

ait lab status LAB_ID
ait intercept evidence --primitive a2a.approval-amount

Lifecycle variations

  • Drop: the specialist and ledger should remain unchanged.
  • Replay: check whether one request produces more than one receiver or ledger entry.
  • REST or gRPC: rerun with --a2a-binding rest or --a2a-binding grpc to separate the security property from one wire binding.

Do not mix a replay result into the amount result. Duplicate processing and value authority are separate claims with separate controls.

Done when

You can point to the original request, the exact diff, receiver state, the effect row, and the close control in one session, and explain why each artifact is needed.

Next: Task and tenant crossover moves from a value inside one request to the identity under which the receiver handles it.