Skip to content

Autonomous Agent Protocols (MCP & A2A)

5.1 Model Context Protocol (MCP) Streamable HTTP

Section titled “5.1 Model Context Protocol (MCP) Streamable HTTP”

DID.is inspects MCP tool servers over Streamable HTTP transports across two normative profiles.

  1. Current Stateless (2026-07-28):
    • Discover: POST / with Mcp-Method: server/discover and MCP-Protocol-Version: 2026-07-28.
    • Tools: POST / with Mcp-Method: tools/list (paginated up to MAX_PAGES = 10, MAX_TOOLS = 500).
    • Client metadata: Carried in _meta containing io.modelcontextprotocol/protocolVersion and clientInfo.
  2. Legacy Session (2025-11-25):
    • Handshake: POST / (initialize) $\to$ POST / (notifications/initialized).
    • Session tracking: Subsequent requests carry Mcp-Session-Id.
    • Teardown: Emits DELETE / to terminate session.

Every tool exposed by an MCP server is assigned dual cryptographic fingerprints:

  • Definition Hash: $$\text{definition_sha256} = \text{hex}(\text{SHA-256}(\text{JCS}(\text{tool_object})))$$
  • Schema Hash: $$\text{schema_sha256} = \text{hex}(\text{SHA-256}(\text{JCS}(\text{tool.inputSchema})))$$
  • Server Inventory Hash: Sort pairs $[[\text{name}_1, \text{hash}_1], [\text{name}_2, \text{hash}_2], \dots]$ by name, canonicalize with JCS, and compute SHA-256: $$\text{inventory_hash} = \text{hex}(\text{SHA-256}(\text{JCS}(\text{sorted_pairs})))$$

5.1.3 Heuristic vs. Declared Risk Classification

Section titled “5.1.3 Heuristic vs. Declared Risk Classification”

DID.is decouples server self-declarations from observed heuristics:

  • Declared Class: Extracted from tool annotations (readOnlyHint, destructiveHint, openWorldHint).
  • Heuristic Class: Independent lexical analysis of tool name, description, and input schema property tokens against precedence: $$\text{system_execution} > \text{write} > \text{network_egress} > \text{read_only}$$
    • system_execution: Matches exec, shell, bash, cmd, spawn, subprocess, sudo, eval, terminal.
    • write: Matches write, create, update, delete, drop, commit, push, deploy, transfer, pay, purchase, revoke.
    • network_egress: Matches fetch, http, url, download, upload, webhook, email, crawl, scrape, slack.
  • Security Signals:
    • Prompt injection heuristics: Scanned for "ignore previous", "system prompt", "<important>", "private key", "api key".
    • Unicode evasion: Scanned for invisible or bidirectional Unicode (e.g. U+200B..U+200F, U+202A..U+202E, U+FEFF, U+E0000..U+E007F).
    • Mismatch alerting: Triggered if declared == "read_only" but heuristic detects write, network_egress, or system_execution.

The Agent-to-Agent (A2A) protocol defines discovery and authentication for autonomous services.

  1. Discovery: Fetches /.well-known/agent-card.json (fallback /.well-known/agent.json), capped at MAX_CARD_BYTES = 512 * 1024 (512 KiB).
  2. Interface Binding: Validates supportedInterfaces[] against known bindings: JSONRPC, GRPC, HTTP+JSON.
  3. Detached JWS Signature Verification:
    • Strips the signatures property from the agent card.
    • Canonicalizes the remaining card object with RFC 8785 (JCS).
    • Verifies detached JWS signatures over the canonical bytes.
    • Resolves signer keys via DID kid (using assertionMethod) or HTTPS jku JWK Set (capped at 128 KiB, validated through SafeHttpClient).