Trango ComputeContextIQ

Agent Protocol Inspector · Scope

What a scan can see, and what it cannot

The Agent Protocol Inspector reads what an MCP server, A2A agent card or ARD catalog publishes. That produces useful evidence for an access review, but only for part of the risk picture. This page maps each check to the OWASP risk entries it informs, and lists the ones it cannot observe at all.

This maps scanner checks to risk-framework entries by risk class. "Informs" means the check produces evidence a reviewer can use; it does not mean the Inspector detects, prevents or covers the risk. A passive, unauthenticated scan reads declarations and configuration, so anything about runtime behaviour is out of its reach.

The OWASP Top 10 for Agentic Applications (ASI) describes agentic applications. The OWASP Agentic Skills Top 10 (AST) describes installable agent skills. The Inspector scans remote MCP, A2A and ARD endpoints, so entries are mapped by risk class, not because it scans those ecosystems.

Checks and the entries they inform

Capability classification

Maps each declared MCP tool or A2A skill to a capability and risk level using fixed keyword rules, and lists skills that matched no rule.

Limit: Based on names and descriptions the target publishes. It does not see what a tool actually does when called.

Tool behaviour hints

Records the read-only, destructive, idempotent and open-world hints an MCP server declares, and notes where a hint conflicts with the name-based classification.

Limit: Hints are unverified server claims. An absent hint is not evidence of safety.

Scope and permission evidence

Shows the scopes a target publishes, labeled per-skill, card-level or server-level, plus input parameters that look like they select an identity or account.

Limit: MCP publishes no per-tool scopes, so most scope evidence is server-level. It shows what is declared, not what a token is granted or how it is used.

Authentication context and findings

Compares what an MCP endpoint does (challenges for auth or answers anonymously) with what an A2A card declares, and checks the OAuth discovery chain it advertises.

Limit: A2A authentication is read from the card; the A2A service itself is not probed.

OAuth posture signals

Reports whether an authorization server publishes FAPI 2.0 related metadata such as PAR, PKCE S256, sender-constrained tokens and approved signing algorithms.

Limit: Published metadata is optional and is a claim, not proof of behaviour. This is not a conformance test or certification.

Description findings

Flags invisible characters, instruction-like phrases, very long text and colliding names in the descriptions a target publishes about its tools and skills.

Limit: Static pattern matching. A match is a reason to read the text, not a verdict, and a clean result does not mean the text is safe.

Definition pins and change since last scan

Hashes each tool or skill definition and, for signed-in users, reports what changed since the previous scan of the same target.

Limit: Detects change between scans you ran. It cannot say whether a change is malicious or what happened between scans.

Agent card signature presence

Reports whether an A2A agent card carries a JWS signature and which algorithm it names.

Limit: Presence only. The signature is not verified and no key is fetched.

Poppy discovery document and issuer cross-check

Reads /.well-known/poppy.json (Personal Agent Protocol Draft 0.1), lints it, and cross-checks auth.issuer against the authorization server metadata: issuer equality, poppy_domains and required endpoints.

Limit: Reads the document as published; the draft can change. The sign-in flows, DPoP enforcement, APIs and conversation endpoint it lists are not called.

Inventory and review packet

Produces a reproducible inventory of declared capabilities, reviewer and owner questions, and CSV exports for identity governance tools.

Limit: It is review evidence. It does not implement approval, enforcement or revocation.

Every entry, accounted for

OWASP Top 10 for Agentic Applications 2026 (ASI)

EntryEvidence the Inspector produces
ASI01 Agent Goal HijackDescription findings
ASI02 Tool MisuseCapability classification; Tool behaviour hints
ASI03 Identity & Privilege AbuseCapability classification; Scope and permission evidence; Authentication context and findings; OAuth posture signals; Poppy discovery document and issuer cross-check
ASI04 Agentic Supply Chain VulnerabilitiesDefinition pins and change since last scan; Agent card signature presence
ASI05 Unexpected Code ExecutionNone: not observable by a passive scan (see below)
ASI06 Memory & Context PoisoningNone: not observable by a passive scan (see below)
ASI07 Insecure Inter-Agent CommunicationAuthentication context and findings; Agent card signature presence
ASI08 Cascading FailuresNone: not observable by a passive scan (see below)
ASI09 Human-Agent Trust ExploitationNone: not observable by a passive scan (see below)
ASI10 Rogue AgentsNone: not observable by a passive scan (see below)

OWASP Agentic Skills Top 10, version 1.0-2026 (AST)

EntryEvidence the Inspector produces
AST01 Malicious SkillsNone: not observable by a passive scan (see below)
AST02 Supply Chain CompromiseNone: not observable by a passive scan (see below)
AST03 Over-Privileged SkillsCapability classification; Tool behaviour hints; Scope and permission evidence
AST04 Insecure MetadataDescription findings
AST05 Untrusted External InstructionsNone: not observable by a passive scan (see below)
AST06 Weak IsolationNone: not observable by a passive scan (see below)
AST07 Update DriftDefinition pins and change since last scan
AST08 Poor ScanningNone: not observable by a passive scan (see below)
AST09 No GovernanceInventory and review packet
AST10 Cross-Platform ReuseNone: not observable by a passive scan (see below)

Not observable by a passive scan

For these, a scan can only say that something exists, never what happens. They need telemetry or a control in the execution path, which is outside what this tool does.

Goal hijack and prompt injection at runtime

Depends on the content an agent reads while it runs.

Needs instead: Runtime inspection of inputs, plans and tool calls

What executes when a tool is called

A scan sees that an execute-style tool is declared, not what it runs or how it is sandboxed.

Needs instead: Sandboxing and execution telemetry

Memory and context poisoning

Happens inside the agent's stores and context.

Needs instead: Provenance and validation of memory writes

Cascading failures

Emerges from live interaction between agents and services.

Needs instead: Runtime monitoring, rate and blast-radius limits

Human-agent trust exploitation

Depends on how an agent talks to the people it works with.

Needs instead: Review of approval flows and user-facing behaviour

Rogue or drifting agent behaviour

Requires behaviour over time.

Needs instead: Behavioural baselines and the ability to stop an agent

Malicious content inside skill packages

The Inspector reads remote endpoints, not installable skill packages.

Needs instead: Package scanning and signing

Provenance of skill packages and dependencies

No package or dependency data is visible from a remote endpoint.

Needs instead: Transparency logs and dependency pinning

Remote content a skill loads at runtime

The Inspector does not follow or evaluate documents a tool says it will read.

Needs instead: Inventory and pinning of referenced sources

Process and container isolation

Isolation is a property of the host, not the endpoint.

Needs instead: Host-level controls

Quality of scanning itself

This is a property of a program's tooling, not of a target.

Needs instead: Multi-tool scanning and review

Skill reuse across agent platforms

Relates to skill packaging formats, not remote endpoints.

Needs instead: A common skill format and platform validation

How tools, tokens and inter-agent messages are used

A passive scan sees declarations and configuration, not tool calls, granted scopes or message contents.

Needs instead: Telemetry from the execution path

Sources: OWASP Top 10 for Agentic Applications 2026, OWASP Agentic Skills Top 10. ContextIQ is not affiliated with or endorsed by OWASP.