HandoffProbe ships 23 adversarial tests for A2A-to-MCP agent handoff security
HeavisideSolutions · reddit · 2026-09-22
An open-source security testing tool, HandoffProbe v0.4.0, targets a subtle problem: handoffs between AI agents across the A2A/MCP boundary can be perfectly valid at the protocol/schema level while still doing something dangerous — widening authority during translation, reusing stale authorization, binding authority to the wrong caller, losing identity/context between agents, or replaying/mutating handoff state.
The release bundles 23 deterministic adversarial cases, runnable locally with a single npm exec command — no signup, no paid API, no model required. The newest case, HP-AUTH-006, checks whether an earlier valid authorization can silently authorize a later, distinct protected effect after that authority is no longer current. The author is soliciting real-world delegation security failures to convert into more deterministic tests.
More from coding & agent
- Moonshot Launches Kimi Browser Extension: Record Steps Once, Agent Replays Forever — Kimi_Moonshot · 2026-09-22
- Jimothy distills LLM queries into tiny task-specific classifiers running 10-20x faster — flngr · 2026-09-22
- What Cloudflare can't do: D1 caps at 10GB, is single-threaded, and no real Postgres — Paimaamu · 2026-09-22
- User Vibecodes Tampermonkey Scripts to Patch Long-Ignored UX Bugs in University Systems — craig_macdonald · 2026-09-22
- Speaking UI layouts into existence with Jev, shadcn and a local transcription model — _AustinCalvert_ · 2026-09-22
- ai-copywriter hits 1k stars: an agent skill that writes converting copy with zero AI tells — tom_doerr · 2026-09-22