Public-Sharing Labels and Verbatim Field Egress in an MCP-to-A2A Agent Configuration: A Controlled Multi-Model Study
cs.CR, cs.AI
Submitted: 2026-09-01
Updated: 2026-09-01
Code: https://github.com/ArpanKumarM/agent-interop-bench
Project page: https://safo-lab.github.io/A2ASecBench
Terminology
Sources
- AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
- Defeating Prompt Injections by Design
- ProtocolBench: Which LLM MultiAgent Protocol to Choose?
- Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection
- MCPHunt: An Evaluation Framework for Cross-Boundary Data Propagation in Multi-Server MCP Agents
- Identifying the Risks of LM Agents with an LM-Emulated Sandbox
- Open Challenges in Multi-Agent Security: Towards Secure Systems of Interacting AI Agents
- MCPSecBench: A Systematic Security Benchmark and Playground for Testing Model Context Protocols
- MCP Security Bench (MSB): Benchmarking Attacks Against Model Context Protocol in LLM Agents
- AgentRFC: Security Design Principles and Conformance Testing for Agent Protocols
- Formal Security Analysis of Agent Protocol Composition
- MCP-SafetyBench: A Benchmark for Safety Evaluation of Large Language Models with Real-World MCP Servers
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs