Characterizing interactions among security features
Characterize how security features interact, determine how those interactions affect security properties, and develop ways to capture the interactions, including interactions that may weaken or violate security properties.
References
Security Gap Analysis between A2A and MCP. While this paper treats A2A and MCP as complementary protocols operating at distinct layers, their combination in production deployments creates a composite attack surface that neither specification addresses in isolation. Future work should systematically characterize the security properties of A2A–MCP integration points: specifically, how trust established at the A2A layer propagates into MCP tool invocations, whether prompt injection at the MCP layer can influence A2A task delegation decisions, and what authorization invariants must hold across the boundary between the two protocols to prevent cross-layer privilege escalation.
But how do security features interact, how do these interactions affect security properties, and how can they be captured?