HandoffProbe ships 23 adversarial tests for A2A-to-MCP agent handoff security

HeavisideSolutions · reddit · 2026-09-22

An open-source security testing tool, HandoffProbe v0.4.0, targets a subtle problem: handoffs between AI agents across the A2A/MCP boundary can be perfectly valid at the protocol/schema level while still doing something dangerous — widening authority during translation, reusing stale authorization, binding authority to the wrong caller, losing identity/context between agents, or replaying/mutating handoff state.

The release bundles 23 deterministic adversarial cases, runnable locally with a single npm exec command — no signup, no paid API, no model required. The newest case, HP-AUTH-006, checks whether an earlier valid authorization can silently authorize a later, distinct protected effect after that authority is no longer current. The author is soliciting real-world delegation security failures to convert into more deterministic tests.

Original post →

More from coding & agent

coding & agent channel →