Skip to content

Agent & Tool Trust (MCP & A2A)

The Agent Trust Workspace (/agents) provides specialized verification tools for the autonomous AI agent economy, focusing on Model Context Protocol (MCP) tool servers and Agent-to-Agent (A2A) protocol documents.

┌────────────────────────────────────────────────────────────────────────────────────────┐
│ AGENT TRUST WORKSPACE (/agents) │
├────────────────────────────┬─────────────────────────────┬─────────────────────────────┤
│ MCP Inspector │ A2A Agent Card Inspector │ Delegation Workspace │
│ Audit Streamable HTTP MCP │ Audit A2A v1.0 card schemas│ Audit multi-hop delegation │
│ servers, tool schemas, and│ and verify cryptographic │ chains, capability scopes, │
│ inventory drift. │ JWS publisher signatures. │ and tool authorizations. │
└────────────────────────────┴─────────────────────────────┴─────────────────────────────┘

Model Context Protocol (MCP) Server Inspection

Section titled “Model Context Protocol (MCP) Server Inspection”

Point the MCP Inspector to any Streamable HTTP MCP endpoint (e.g., https://mcp.example.com/mcp):

  1. Stateless Protocol Negotiation: DID.is negotiates current MCP specification 2026-07-28 (server/discover, followed by paginated tools/list carrying MCP-Protocol-Version and Mcp-Method headers). If unsupported, it gracefully falls back to legacy 2025-11-25 session initialization (initialize $\rightarrow$ notifications/initialized).
  2. Bounds & Safety: Paginates up to 10 pages, auditing a maximum of 500 tools. Response bodies are capped at 2 MiB.

Cryptographic Tool Fingerprints & Inventory Hashes

Section titled “Cryptographic Tool Fingerprints & Inventory Hashes”

For every discovered tool, DID.is computes deterministic digests:

  • definitionSha256: The SHA-256 hash of the tool’s canonical RFC 8785 JSON definition.
  • schemaSha256: The SHA-256 hash of the tool’s input parameter schema.
  • inventoryHash: A sorted, composite SHA-256 hash representing the server’s entire tool catalog.

Autonomous agents face severe security risks when tool providers quietly alter schemas, inject unvetted parameters, or change tool behaviors after onboarding. DID.is stores historical snapshots in SQLite and reports comparative drift:

  • FIRST_OBSERVATION: Initial baseline recorded for this endpoint.
  • UNCHANGED: All tool definitions and input schemas exactly match the baseline.
  • ADDED: New tools added to the server catalog.
  • REMOVED: Tools withdrawn by the provider.
  • CHANGED: Existing tool parameters or descriptions were modified (potential schema poisoning).
  • PROFILE_CHANGED: Server changed canonical fingerprint algorithms; not a behavioral rug-pull.

Declared vs. Heuristic Side-Effect Classification

Section titled “Declared vs. Heuristic Side-Effect Classification”

Tool servers often understate the risks of their tools in metadata annotations. DID.is audits tools along two parallel tracks:

┌────────────────────────────────────────────────────────────────────────────────────────┐
│ TOOL SIDE-EFFECT RATIO │
├────────────────────────────────────────────────────────────────────────────────────────┤
│ [■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■] │
│ ■ Read-only (45) ■ Network Egress (12) ■ State Write (8) ■ System Exec (2) │
└────────────────────────────────────────────────────────────────────────────────────────┘
  1. declaredClass: What the server claims in its annotations (read_only, write).
  2. heuristicClass: Independent classification derived by DID.is from input property names, required parameters, and action verbs (read_only, network_egress, write, system_execution).
  3. Discrepancy Reporting: If a tool claims to be “read-only” but its parameter schema accepts rawCommand or destinationUrl, DID.is raises an explicit Risk Signal Warning.

DID.is strictly performs unauthenticated inspection:

  • If an MCP endpoint requires authorization, it receives an HTTP 401 Unauthorized.
  • DID.is reports status AUTH_REQUIRED alongside the server’s WWW-Authenticate challenge and protected-resource metadata.
  • DID.is never prompts users for OAuth tokens, never proxies bearer credentials, and never transmits secrets to third-party endpoints.

Agent-to-Agent (A2A) Protocol Card Inspection

Section titled “Agent-to-Agent (A2A) Protocol Card Inspection”

The A2A tab audits agent profile discovery cards:

  1. Discovery Fallback: Fetches /.well-known/agent-card.json (falling back to /.well-known/agent.json), enforcing a 512 KiB streaming cap.
  2. Cryptographic Signature Verification: Validates JWS detached or embedded signatures over the canonical RFC 8785 card content.
  3. Key Resolution: Resolves verification keys from DID URLs (kid) authorized under assertionMethod, or from HTTPS JWK Sets (jku).
  4. Interface Audit: Validates declared protocol bindings (JSON-RPC, REST, SSE), verifying that endpoints enforce HTTPS and reside on approved origins.