Agents
A2A Contagion: Agent Card Shadowing, Impersonation, and Capability Hijacking Define 2026's Evolved Attack Playbook
The attack vector evolution is now documented: 2024 saw direct prompt injection, 2025 shifted to indirect prompt injection via poisoned documents, and 2026's primary attack surface is the agent-to-agent handoff itself. New techniques include agent card shadowing (unauthorized cloning of a legitimate agent's skill advertisement to intercept task assignments), agent impersonation (adversarial agents mimicking trusted agent identity and interaction patterns), and capability hijacking (compromised agents with inflated skill advertisements capturing disproportionate task load). These attacks exploit the absence of identity management and request-level integrity verification in the A2A protocol.
↳ Follow the thread