Agent Handoff Boundary

What this is. Agent handoffs are egress events, not chat messages. This pack makes the boundary explicit: what may cross, which protocol is allowed, which data classes trigger redaction or approval, and which payload fields terminate the session.

Rechecked October 5, 2026 against A2A Protocol 1.0.0 (latest still resolves to 1.0.0). Section 3.6.1 says clients MUST send A2A-Version Major.Minor with each request. Section 3.6.2 says servers MUST interpret an empty value as 0.3 and MUST return VersionNotSupportedError when the version is unsupported. Section 7.6 says TASK_STATE_AUTH_REQUIRED credentials MUST arrive out of band unless an in-band mechanism was negotiated; credentials in the A2A message can leak across agent chains. This pack now holds missing or 0.3 version headers, denies unsupported versions, holds AUTH_REQUIRED handoffs without an out-of-band channel, and kills in-band credentials that were not negotiated. MCP, provider-native, and human-approval surfaces, and A2A requests that omit task_state, stay on their prior path. This pass does not claim human review of the pack.

SecurityRecipes is positioned as The Secure Context Layer for Agentic AI. That claim has to hold when one agent delegates to another agent, not only when a single agent retrieves context through MCP.

The Agent Handoff Boundary Pack is the protocol trust layer between secure context retrieval and multi-agent execution. It gives platform teams a machine-readable contract for MCP tool calls, A2A task delegations, provider-native subagents, and human approval bridges.

What was added

  • data/assurance/agent-handoff-boundary-model.json - source model for protocols, profiles, payload fields, data classes, and decisions.
  • data/evidence/agent-handoff-boundary-pack.json - generated evidence pack for CI, MCP, platform review, and diligence.
  • MCP tools: recipes_agent_handoff_boundary_pack, paired with recipes_playbook_plan using playbook id agent-handoff-boundary.

Regenerate and validate:

python3 scripts/generate_agent_handoff_boundary_pack.py
python3 scripts/generate_agent_handoff_boundary_pack.py --check

Evaluate a metadata-only A2A handoff:

python3 scripts/evaluate_agent_handoff_boundary_decision.py \
  --workflow-id vulnerable-dependency-remediation \
  --handoff-profile-id metadata-only \
  --protocol a2a_task_delegation \
  --target-trust-tier approved_vendor \
  --agent-card-signed \
  --authentication-scheme oauth2 \
  --a2a-version 1.0 \
  --payload-field task_summary \
  --payload-field workflow_id \
  --payload-field source_ids \
  --payload-field source_hashes \
  --payload-field correlation_id \
  --data-class curated_security_guidance \
  --expect-decision allow_metadata_handoff

Hold a production-looking A2A metadata handoff that omits A2A-Version (empty is 0.3):

python3 scripts/evaluate_agent_handoff_boundary_decision.py \
  --workflow-id vulnerable-dependency-remediation \
  --handoff-profile-id metadata-only \
  --protocol a2a_task_delegation \
  --target-trust-tier approved_vendor \
  --agent-card-signed \
  --authentication-scheme oauth2 \
  --payload-field task_summary \
  --payload-field workflow_id \
  --payload-field source_ids \
  --payload-field source_hashes \
  --payload-field correlation_id \
  --data-class curated_security_guidance \
  --expect-decision hold_for_redaction_or_approval

Kill an AUTH_REQUIRED handoff that puts credentials in the A2A message:

python3 scripts/evaluate_agent_handoff_boundary_decision.py \
  --workflow-id vulnerable-dependency-remediation \
  --handoff-profile-id metadata-only \
  --protocol a2a_task_delegation \
  --target-trust-tier approved_vendor \
  --agent-card-signed \
  --authentication-scheme oauth2 \
  --a2a-version 1.0 \
  --task-state TASK_STATE_AUTH_REQUIRED \
  --credentials-in-a2a-message \
  --payload-field task_summary \
  --payload-field workflow_id \
  --payload-field source_ids \
  --payload-field source_hashes \
  --payload-field correlation_id \
  --data-class curated_security_guidance \
  --expect-decision kill_session_on_secret_handoff

Workflow at a glance

Agent Handoff Boundary workflow

Decide what context and authority may cross an MCP, A2A, provider-subagent, or human-approval handoff.

agent-runtime
  1. Signal

    Receive a handoff request

    Capture source and target agents, protocol, task, payload, data classes, authority, and correlation identifiers.

  2. Scope

    Classify the payload

    Separate metadata, cited evidence, private context, memory, prompts, tool traces, credentials, and customer data.

  3. Decision

    Match a handoff profile

    Require target trust, A2A-Version 1.0, out-of-band AUTH_REQUIRED credentials, protocol conformance, purpose, approvals, egress policy, and the minimum necessary fields.

  4. Action

    Transform or block

    Allow metadata/cited evidence, redact fields, require approval, deny delegation, or terminate on prohibited content.

  5. Proof

    Write the handoff receipt

    Record source hashes, transformations, authority, decision, destination, expiry, and downstream obligations.

Decision gate

Is the target trusted, is A2A-Version 1.0 present, and is every payload field permitted for this protocol, purpose, and approval state?

Proceed

Send only the approved minimized payload and authority.

Hold or stop

Hold, deny, or kill when trust, version, AUTH_REQUIRED channel, purpose, approval, or prohibited-data checks fail.

Evidence to retain

  • source/target trust records
  • payload classification and redactions
  • handoff decision receipt

Expected outputs

  • bounded handoff packet
  • approval request
  • denial/kill record

Handoff profiles

Profile Default decision Use when
metadata-only allow_metadata_handoff A remote agent needs a task summary, workflow ID, source IDs, source hashes, and correlation ID only.
cited-evidence allow_cited_evidence_handoff A delegated agent needs redacted evidence plus source hashes and egress decision state.
approval-gated allow_approved_handoff The target agent receives high-impact task context after explicit approval and scoped authority.
prohibited-context kill_session_on_secret_handoff Credential material, internal memory, hidden prompts, raw tool traces, or unrestricted customer data appear.

Why it is review-ready

MCP and A2A are becoming the enterprise interoperability substrate for agentic systems. A reviewer or reviewer will ask whether SecurityRecipes can govern that substrate, not just document it.

This pack answers concrete diligence questions:

  • Can handoffs fail closed by default?
  • Can a remote agent receive only the minimum context required?
  • Can MCP and A2A controls be represented in the same decision model?
  • Can high-impact delegated work require explicit approval?
  • Can the product kill sessions when hidden prompts, memory, raw traces, credentials, or signing material are about to cross a boundary?

The trusted-source path is hosted handoff enforcement, signed Agent Card trust, agent-to-agent replay, tenant evidence ingestion, approval receipts, and trust-center exports.

Industry alignment

This layer is anchored in current primary guidance:

MCP examples

List handoff profiles:

{}

Inspect one workflow map:

{
  "workflow_id": "vulnerable-dependency-remediation"
}

Evaluate an approval-gated handoff:

{
  "workflow_id": "artifact-cache-quarantine",
  "handoff_profile_id": "approval-gated",
  "protocol": "a2a_task_delegation",
  "target_trust_tier": "approved_vendor",
  "agent_card_signed": true,
  "authentication_schemes": ["oauth2"],
  "a2a_version": "1.0",
  "payload_fields": [
    "task_summary",
    "workflow_id",
    "source_ids",
    "source_hashes",
    "approval_record_id",
    "delegated_authority",
    "correlation_id"
  ],
  "data_classes": ["customer_ticket_summary", "approval_record"],
  "requested_capabilities": ["ticket_write"],
  "human_approval_record": {
    "approval_id": "approval-123",
    "status": "approved"
  }
}

See also