A2A to MCP boundary playbook¶
Methodology, not an executable workflow. This page defines a trust boundary, close control, and evidence requirement. The operator must implement it against a specific authorized target; no command here claims to execute the full chain.
Use this playbook when an A2A agent delegates work that crosses into MCP tools, resources, sampling, or elicitation. Place the A2A relay explicitly and place Seam on the MCP stdio or Streamable HTTP connection. Deposit the complete plan before contact.
Routes¶
boundary.a2a-mcp-tool-argument-escalation: compare delegated intent with the delivered MCP arguments.boundary.a2a-artifact-mcp-resource-poisoning: track an A2A artifact into MCP resource context.boundary.mcp-result-a2a-artifact-laundering: track a mutated tool result into an A2A artifact and consumer.boundary.a2a-mcp-identity-context-loss: compare actor, tenant, audience, resource, scope, and credential epoch.boundary.mcp-elicitation-principal-confusion: bind elicitation to the initiating A2A principal.boundary.mcp-sampling-delegation-manipulation: inspect samplingtoolChoiceand later delegation.boundary.a2a-cancel-surviving-mcp-effect: cancel the A2A task and inspect the controlled MCP effect ledger.boundary.mcp-late-result-a2a-overwrite: compare artifact revision and MCP result timing using explicit identifiers.boundary.a2a-extension-mcp-tool-bypass: compare the extension claim with the MCP tool policy decision.boundary.mcp-schema-a2a-aggregate-differential: compare MCP schema validation with aggregate acceptance.
Procedure¶
Run the attack, identical close control, explicit miss, and necessary boundary ablation with fresh relay, MCP wrapper, session, state, and oracle. Inspect ait.agent-tool-transaction/v1. It must contain A2A and MCP record references, a deposited handoff, shared identifiers, authority before and after, changed paths, and the hash-chain links.
Target acceptance, model text, framework traces, and temporal inference do not prove impact. Require a callback, action ledger, datastore change, transaction record, or tool event.
Troubleshooting¶
If correlation fails, verify the A2A task/context identifiers were deposited into the MCP request metadata and that both the relay and Seam record references exist. Do not repair evidence with a timing-based link. If authority changes unexpectedly, inspect the exact boundary handoff and credential epoch before rerunning the control.