Security researchers documented Agent Card Poisoning — a metadata injection vulnerability where malicious remote agents embed adversarial instructions in their A2A agent cards. Since agent cards are injected directly into LLM reasoning context without strict boundary enforcement, metadata gets reinterpreted as executable instruction. The A2A protocol delegates credential management entirely to implementers, meaning agent impersonation, card tampering, and replay attacks are real risks without additional controls.