MCP/A2A Skill Description Leakage and IP/Prompt Exposure in Multi-Agent Coordination
lowAgentProtocol VulnerabilityThis is an academic research paper proposing a new protocol-layer defense (Skill-as-API) rather than a report of an active exploit. It identifies a legitimate design weakness in current agent coordination protocols like MCP and A2A: they expose full skill descriptions, schemas, and potentially system prompts to all peers, and offer no mechanism to hide skill existence or narrow the prompt-injection surface structurally. Severity is low because this is a proactive mitigation proposal, not evidence of exploitation in the wild.
Updated Sep 3, 2026