Delegated A2A message¶
A2A request sender → receiver value authority 20–30 minutes
A gateway delegates a controlled approval to a specialist. The exercise asks a precise question: can a value change after the sender creates the request but before the receiver acts on it?
| Recipe | Value |
|---|---|
| Pause | message/send request |
| Attack | amount 25 → 75 |
| Control | change only human-readable message text |
| Receiver proof | specialist state |
| Out-of-band proof | approval effect ledger |
amount 25 AIT
edit request Specialist
reads amount MCP
policy Ledger
records action
Start the target¶
In the Lab drawer, select Send exercise traffic. One pending A2A request
should appear. Confirm its operation is message/send and its direction is
from gateway to specialist before editing anything.
Run the attack arm¶
- Open the pending request in the structured editor.
- Find
/params/message/metadata/amount; its baseline value is25. - Set the arm to attack.
- Change the value to
75and inspect the diff. - Select Forward modified.
- Open receiver state and the effect ledger in the Lab drawer.
The specialist state proves the receiver parsed the delivered amount. The approval ledger proves the controlled receiver acted with that amount. A modified request in the traffic timeline proves neither on its own.
Run the close control¶
Trigger the same exercise again without resetting the session. Change only the
human-readable text in the message and leave metadata.amount at 25. Mark
this message as the control arm and forward it.
The control crosses the same process and protocol boundary, is visible to the same receiver, and differs from the attack in the authority-bearing field. If it moves the recorded amount too, the result is not isolated to amount authority.
Read the evidence¶
| Observation | What it establishes | What it does not establish |
|---|---|---|
| edited request in AIT | the mutation was formed | that the receiver accepted it |
specialist state shows 75 |
the receiver processed the mutation | that an action occurred |
approval ledger shows 75 |
the controlled action used the delivered value | behavior on another target |
text-only control remains 25 |
the tested field, not any edit, explains the change | a general A2A vulnerability |
Use status when you want the same evidence in the terminal:
Lifecycle variations¶
- Drop: the specialist and ledger should remain unchanged.
- Replay: check whether one request produces more than one receiver or ledger entry.
- REST or gRPC: rerun with
--a2a-binding restor--a2a-binding grpcto separate the security property from one wire binding.
Do not mix a replay result into the amount result. Duplicate processing and value authority are separate claims with separate controls.
Done when¶
You can point to the original request, the exact diff, receiver state, the effect row, and the close control in one session, and explain why each artifact is needed.
Next: Task and tenant crossover moves from a value inside one request to the identity under which the receiver handles it.