Agentic Protocol Conformance Pack

Why this page exists. MCP and A2A make agent systems composable. Enterprise trust depends on proving those protocol boundaries are current, reviewed, and enforced before context, authority, tools, or remote-agent delegation crosses them.

SecurityRecipes is positioned as The Secure Context Layer for Agentic AI. The secure context layer cannot stop at content provenance. It also needs protocol conformance: the evidence that MCP authorization metadata, tool annotations, tool-surface drift, A2A Agent Cards, authenticated extended cards, identity, handoff, egress, and prompt-injection source to sink controls are current and fail closed.

The Agentic Protocol Conformance Pack turns fast-moving protocol and agent-security guidance into a generated artifact that a platform team, or procurement reviewer can inspect through MCP. Rechecked against MCP 2026-07-28 on August 23, 2026. --protocol-id mcp-authorization-2025-11-25 is the existing pack id. It is not a 2026 protocol-profile clone and not a claim that 2025-11-25 is still the current MCP specification.

Rechecked September 27, 2026 against the MCP 2026-07-28 subscriptions pattern and changelog. subscriptions/listen replaced resources/subscribe and the HTTP GET notification endpoint. Servers must send notifications/subscriptions/acknowledged with io.modelcontextprotocol/subscriptionId before any event, must not push unrequested notification types, and must keep request-scoped notifications/progress and notifications/message on the originating request stream. After a stdio reconnect, clients must re-send subscriptions/listen. This editorial pass does not claim a separate human review of the pack.

What was added

  • Source profile: data/assurance/agentic-protocol-conformance-profile.json
  • Generator: scripts/generate_agentic_protocol_conformance_pack.py
  • Evidence pack: data/evidence/agentic-protocol-conformance-pack.json
  • Runtime evaluator: scripts/evaluate_agentic_protocol_conformance_decision.py
  • MCP tools: recipes_agentic_protocol_conformance_pack, paired with recipes_playbook_plan using playbook id agentic-protocol-conformance.

Regenerate and validate:

python3 scripts/generate_agentic_protocol_conformance_pack.py
python3 scripts/generate_agentic_protocol_conformance_pack.py --check

Evaluate an MCP authorization boundary:

python3 scripts/evaluate_agentic_protocol_conformance_decision.py \
  --protocol-id mcp-authorization-2025-11-25 \
  --workflow-id vulnerable-dependency-remediation \
  --agent-id sec-auto-remediator \
  --run-id run-2026-05-04-001 \
  --session-id sess-001 \
  --correlation-id corr-001 \
  --transport streamable-http \
  --resource-indicator-present \
  --token-audience-bound \
  --pkce-verified \
  --client-metadata-reviewed \
  --expect-decision allow_with_protocol_receipt

Deny an unsolicited subscriptions/listen notification:

python3 scripts/evaluate_agentic_protocol_conformance_decision.py \
  --protocol-id mcp-tooling-safety \
  --workflow-id vulnerable-dependency-remediation \
  --agent-id sec-auto-remediator \
  --run-id run-2026-09-27-listen \
  --session-id sess-listen \
  --correlation-id corr-listen \
  --transport streamable-http \
  --tool-surface-pinned \
  --tool-annotations-trusted \
  --subscription-method subscriptions/listen \
  --subscription-id 1 \
  --subscription-acknowledged \
  --subscription-unsolicited-notification \
  --expect-decision deny_untrusted_protocol_surface

Workflow at a glance

Agentic Protocol Conformance Pack workflow

Test MCP, A2A, auth, lifecycle, transport, capability, error, and boundary behavior against declared protocol profiles.

agent-assurance
  1. Signal

    Select a protocol surface

    Identify implementation, version, transport, roles, auth, capabilities, extensions, lifecycle, and target environment.

  2. Scope

    Build conformance cases

    Choose discover, subscriptions/listen, schema, authorization, cancellation, error, retry, handoff, and security-boundary tests. Treat resources/subscribe and HTTP GET notifications as 2026-07-28 drift.

  3. Decision

    Execute safe probes

    Run fixtures against isolated or read-only endpoints and capture requests, responses, decisions, timing, and deviations.

  4. Action

    Classify conformance

    Mark pass, restricted, hold, deny, or kill behavior and separate protocol defects from security-policy violations.

  5. Proof

    Publish the pack

    Record implementation/version, case results, evidence hashes, exceptions, owners, remediation, and recertification triggers.

Decision gate

Does the implementation satisfy required protocol and security-boundary cases for its deployment profile?

Proceed

Approve the tested profile and declared extensions.

Hold or stop

Restrict or deny deployments with auth, lifecycle, capability, or boundary failures.

Evidence to retain

  • versioned conformance cases
  • request/response and decision results
  • exceptions and remediation

Expected outputs

  • protocol conformance pack
  • restricted deployment profile
  • defect backlog

Decision model

Decision Meaning
allow_with_protocol_receipt Protocol evidence is current enough to proceed and can be attached to the run receipt.
hold_for_protocol_evidence Required metadata, identity, consent, Agent Card, approval, or evidence-pack state is missing.
hold_for_protocol_drift_review The observed protocol version, tool surface, annotations, or schema drift requires review.
deny_unbound_protocol_authority MCP authority is not bound to the expected protected resource, audience, or PKCE evidence.
deny_untrusted_protocol_surface A protocol path combines unsafe trust boundaries such as untrusted content, private data, external egress, or unauthenticated remote-agent delegation.
kill_session_on_protocol_violation The request includes token passthrough, secret movement, or an explicit runtime kill signal.

What the pack proves

The generated pack joins existing SecurityRecipes evidence into four protocol profiles:

  • MCP Authorization Conformance for protected-resource metadata, audience and resource binding, PKCE, token-passthrough denial, client metadata review, and incremental consent evidence.
  • MCP Tool Annotation, Schema, and Drift Safety for trusted annotations, pinned tool descriptions and schemas, subscriptions/listen acknowledgment and requested-type enforcement, tool-output validation, and private-data plus untrusted-content plus external-send risk.
  • A2A Agent Discovery and Delegation for Agent Card completeness, authenticated extended cards, HTTPS transport, version headers, signed card evidence, skill trust, and handoff minimization.
  • Agent Identity, Protocol Handoff, and Prompt-Injection Boundary for non-human identity, run receipts, egress policy, source-to-sink prompt injection defenses, and standards-drift review.

Industry alignment

This feature tracks current primary guidance:

  • MCP Authorization for protected-resource metadata, resource indicators, audience-bound tokens, PKCE, client metadata, and token-passthrough denial.
  • MCP Subscriptions for subscriptions/listen, notifications/subscriptions/acknowledged, io.modelcontextprotocol/subscriptionId, requested notification types, and stdio reconnect behavior.
  • MCP Tool Annotations for annotation-driven tool UX and the need to treat annotations as policy hints until trust and drift evidence exist.
  • A2A Protocol Specification for Agent Cards, authenticated extended cards, security schemes, version headers, and transport requirements.
  • NIST AI Agent Standards Initiative for interoperable agent standards, authentication, identity infrastructure, and security evaluations.
  • NIST CAISI AI Agent Security RFI for indirect prompt injection, poisoning, misaligned actions, and deployment access controls.
  • OWASP Top 10 for Agentic Applications 2026 for tool misuse, identity abuse, context poisoning, insecure inter-agent communication, cascading failures, and rogue agents.
  • OpenAI prompt-injection guidance for source-to-sink reasoning, constrained impact, confirmations, and data-transmission safeguards.

Trusted-source path

The open pack is the proof model. The reviewed production surface is hosted MCP and A2A protocol conformance:

  • live MCP protected-resource metadata checks,
  • client metadata and redirect-policy review,
  • resource, audience, PKCE, consent, and scope-drift monitoring,
  • signed tool-surface baselines and annotation drift alerts,
  • A2A Agent Card monitoring, signature verification, and skill allowlists,
  • source-to-sink prompt-injection policy across protocol boundaries,
  • signed protocol receipts attached to agent run receipts,
  • procurement and trust review diligence exports.

That turns SecurityRecipes from a static knowledge base into a protocol control plane a model lab, AI platform vendor, or security team can inspect and operate.

MCP examples

Inspect the overall pack:

recipes_agentic_protocol_conformance_pack()

Review one protocol profile:

recipes_agentic_protocol_conformance_pack(
  protocol_id="mcp-tooling-safety"
)

Plan one A2A boundary:

recipes_playbook_plan(
  playbook_id="agentic-protocol-conformance",
  finding="A2A agent discovery handoff needs protocol conformance review."
)

See also