Beyond the Mandate: A Systematic Security Analysis of the Agent Payments Protocol (AP2)
cs.CR, cs.AI
Submitted: 2026-08-24
Updated: 2026-08-24
Code: https://github.com/mrwadams/stride-gpt
Terminology
Sources
- Secure Autonomous Agent Payments: Verifying Authenticity and Intent in a Trustless Environment
- ASTRIDE: A Security Threat Modeling Platform for Agentic-AI Applications
- STRIDE-AI: A Threat Modeling Framework for Generative AI Security Assessment
- Whispers of Wealth: Red-Teaming Google's Agent Payments Protocol via Prompt Injection
- Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
- Inter-Agent Trust Models: A Comparative Study of Brief, Claim, Proof, Stake, Reputation and Constraint in Agentic Web Protocol Design-A2A, AP2, ERC-8004, and Beyond
- Model Context Protocol Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning
- Semantic Attacks on Tool-Augmented LLMs: Securing the Model Context Protocol Against Descriptor-Level Manipulation
- Zero-Trust Runtime Verification for Agentic Payment Protocols: Mitigating Replay and Context-Binding Failures in AP2
- Security Analysis of Agentic AI Communication Protocols: A Comparative Evaluation
- Breaking the Protocol: Security Analysis of the Model Context Protocol Specification and Prompt Injection Vulnerabilities in Tool-Integrated LLM Agents
- SoK: Security of Autonomous LLM Agents in Agentic Commerce
- Enterprise-Grade Security for the Model Context Protocol (MCP): Frameworks and Mitigation Strategies
- Securing Agentic AI: A Comprehensive Threat Model and Mitigation Framework for Generative AI Agents
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs