Agent & Tool Trust (MCP & A2A)
6. Autonomous Agent & Tool Trust
Section titled “6. Autonomous Agent & Tool Trust”The Agent Trust Workspace (/agents) provides specialized verification tools for the autonomous AI agent economy, focusing on Model Context Protocol (MCP) tool servers and Agent-to-Agent (A2A) protocol documents.
┌────────────────────────────────────────────────────────────────────────────────────────┐│ AGENT TRUST WORKSPACE (/agents) │├────────────────────────────┬─────────────────────────────┬─────────────────────────────┤│ MCP Inspector │ A2A Agent Card Inspector │ Delegation Workspace ││ Audit Streamable HTTP MCP │ Audit A2A v1.0 card schemas│ Audit multi-hop delegation ││ servers, tool schemas, and│ and verify cryptographic │ chains, capability scopes, ││ inventory drift. │ JWS publisher signatures. │ and tool authorizations. │└────────────────────────────┴─────────────────────────────┴─────────────────────────────┘Model Context Protocol (MCP) Server Inspection
Section titled “Model Context Protocol (MCP) Server Inspection”Point the MCP Inspector to any Streamable HTTP MCP endpoint (e.g., https://mcp.example.com/mcp):
- Stateless Protocol Negotiation: DID.is negotiates current MCP specification
2026-07-28(server/discover, followed by paginatedtools/listcarryingMCP-Protocol-VersionandMcp-Methodheaders). If unsupported, it gracefully falls back to legacy2025-11-25session initialization (initialize$\rightarrow$notifications/initialized). - Bounds & Safety: Paginates up to 10 pages, auditing a maximum of 500 tools. Response bodies are capped at 2 MiB.
Cryptographic Tool Fingerprints & Inventory Hashes
Section titled “Cryptographic Tool Fingerprints & Inventory Hashes”For every discovered tool, DID.is computes deterministic digests:
definitionSha256: The SHA-256 hash of the tool’s canonical RFC 8785 JSON definition.schemaSha256: The SHA-256 hash of the tool’s input parameter schema.inventoryHash: A sorted, composite SHA-256 hash representing the server’s entire tool catalog.
Tool Drift & Rug-Pull Detection
Section titled “Tool Drift & Rug-Pull Detection”Autonomous agents face severe security risks when tool providers quietly alter schemas, inject unvetted parameters, or change tool behaviors after onboarding. DID.is stores historical snapshots in SQLite and reports comparative drift:
FIRST_OBSERVATION: Initial baseline recorded for this endpoint.UNCHANGED: All tool definitions and input schemas exactly match the baseline.ADDED: New tools added to the server catalog.REMOVED: Tools withdrawn by the provider.CHANGED: Existing tool parameters or descriptions were modified (potential schema poisoning).PROFILE_CHANGED: Server changed canonical fingerprint algorithms; not a behavioral rug-pull.
Declared vs. Heuristic Side-Effect Classification
Section titled “Declared vs. Heuristic Side-Effect Classification”Tool servers often understate the risks of their tools in metadata annotations. DID.is audits tools along two parallel tracks:
┌────────────────────────────────────────────────────────────────────────────────────────┐│ TOOL SIDE-EFFECT RATIO │├────────────────────────────────────────────────────────────────────────────────────────┤│ [■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■] ││ ■ Read-only (45) ■ Network Egress (12) ■ State Write (8) ■ System Exec (2) │└────────────────────────────────────────────────────────────────────────────────────────┘declaredClass: What the server claims in its annotations (read_only,write).heuristicClass: Independent classification derived by DID.is from input property names, required parameters, and action verbs (read_only,network_egress,write,system_execution).- Discrepancy Reporting: If a tool claims to be “read-only” but its parameter schema accepts
rawCommandordestinationUrl, DID.is raises an explicit Risk Signal Warning.
OAuth & Unauthenticated Egress Safety
Section titled “OAuth & Unauthenticated Egress Safety”DID.is strictly performs unauthenticated inspection:
- If an MCP endpoint requires authorization, it receives an HTTP
401 Unauthorized. - DID.is reports status
AUTH_REQUIREDalongside the server’sWWW-Authenticatechallenge and protected-resource metadata. - DID.is never prompts users for OAuth tokens, never proxies bearer credentials, and never transmits secrets to third-party endpoints.
Agent-to-Agent (A2A) Protocol Card Inspection
Section titled “Agent-to-Agent (A2A) Protocol Card Inspection”The A2A tab audits agent profile discovery cards:
- Discovery Fallback: Fetches
/.well-known/agent-card.json(falling back to/.well-known/agent.json), enforcing a 512 KiB streaming cap. - Cryptographic Signature Verification: Validates JWS detached or embedded signatures over the canonical RFC 8785 card content.
- Key Resolution: Resolves verification keys from DID URLs (
kid) authorized underassertionMethod, or from HTTPS JWK Sets (jku). - Interface Audit: Validates declared protocol bindings (JSON-RPC, REST, SSE), verifying that endpoints enforce HTTPS and reside on approved origins.