Google's Agent2Agent (A2A) protocol, contributed to the Linux Foundation in 2025 with support from AWS, Microsoft, and others, aims to enable agent-to-agent collaboration through a group chat model. However, adoption has been slow due to fundamental business challenges around data sharing and trust when agents belong to different organizations, extending beyond what technical standards alone can solve.
A2ABreak presents the first systematic security analysis of the A2A protocol, an open standard for autonomous AI agent communication governed by the Linux Foundation. The analysis uncovers 11 new vulnerabilities including cross-client context injection, credential harvesting, and data exfiltration, demonstrating that formal verification methods are essential for protocol security analysis.