Agent Protocol Inspector · Scope
What a scan can see, and what it cannot
The Agent Protocol Inspector reads what an MCP server, A2A agent card or ARD catalog publishes. That produces useful evidence for an access review, but only for part of the risk picture. This page maps each check to the OWASP risk entries it informs, and lists the ones it cannot observe at all.
This maps scanner checks to risk-framework entries by risk class. "Informs" means the check produces evidence a reviewer can use; it does not mean the Inspector detects, prevents or covers the risk. A passive, unauthenticated scan reads declarations and configuration, so anything about runtime behaviour is out of its reach.
The OWASP Top 10 for Agentic Applications (ASI) describes agentic applications. The OWASP Agentic Skills Top 10 (AST) describes installable agent skills. The Inspector scans remote MCP, A2A and ARD endpoints, so entries are mapped by risk class, not because it scans those ecosystems.
Checks and the entries they inform
Capability classification
Maps each declared MCP tool or A2A skill to a capability and risk level using fixed keyword rules, and lists skills that matched no rule.
Limit: Based on names and descriptions the target publishes. It does not see what a tool actually does when called.
Tool behaviour hints
Records the read-only, destructive, idempotent and open-world hints an MCP server declares, and notes where a hint conflicts with the name-based classification.
Limit: Hints are unverified server claims. An absent hint is not evidence of safety.
Scope and permission evidence
Shows the scopes a target publishes, labeled per-skill, card-level or server-level, plus input parameters that look like they select an identity or account.
Limit: MCP publishes no per-tool scopes, so most scope evidence is server-level. It shows what is declared, not what a token is granted or how it is used.
Authentication context and findings
Compares what an MCP endpoint does (challenges for auth or answers anonymously) with what an A2A card declares, and checks the OAuth discovery chain it advertises.
Limit: A2A authentication is read from the card; the A2A service itself is not probed.
OAuth posture signals
Reports whether an authorization server publishes FAPI 2.0 related metadata such as PAR, PKCE S256, sender-constrained tokens and approved signing algorithms.
Limit: Published metadata is optional and is a claim, not proof of behaviour. This is not a conformance test or certification.
Description findings
Flags invisible characters, instruction-like phrases, very long text and colliding names in the descriptions a target publishes about its tools and skills.
Limit: Static pattern matching. A match is a reason to read the text, not a verdict, and a clean result does not mean the text is safe.
Definition pins and change since last scan
Hashes each tool or skill definition and, for signed-in users, reports what changed since the previous scan of the same target.
Limit: Detects change between scans you ran. It cannot say whether a change is malicious or what happened between scans.
Agent card signature presence
Reports whether an A2A agent card carries a JWS signature and which algorithm it names.
Limit: Presence only. The signature is not verified and no key is fetched.
Poppy discovery document and issuer cross-check
Reads /.well-known/poppy.json (Personal Agent Protocol Draft 0.1), lints it, and cross-checks auth.issuer against the authorization server metadata: issuer equality, poppy_domains and required endpoints.
Limit: Reads the document as published; the draft can change. The sign-in flows, DPoP enforcement, APIs and conversation endpoint it lists are not called.
Inventory and review packet
Produces a reproducible inventory of declared capabilities, reviewer and owner questions, and CSV exports for identity governance tools.
Limit: It is review evidence. It does not implement approval, enforcement or revocation.
Every entry, accounted for
OWASP Top 10 for Agentic Applications 2026 (ASI)
| Entry | Evidence the Inspector produces |
|---|---|
| ASI01 Agent Goal Hijack | Description findings |
| ASI02 Tool Misuse | Capability classification; Tool behaviour hints |
| ASI03 Identity & Privilege Abuse | Capability classification; Scope and permission evidence; Authentication context and findings; OAuth posture signals; Poppy discovery document and issuer cross-check |
| ASI04 Agentic Supply Chain Vulnerabilities | Definition pins and change since last scan; Agent card signature presence |
| ASI05 Unexpected Code Execution | None: not observable by a passive scan (see below) |
| ASI06 Memory & Context Poisoning | None: not observable by a passive scan (see below) |
| ASI07 Insecure Inter-Agent Communication | Authentication context and findings; Agent card signature presence |
| ASI08 Cascading Failures | None: not observable by a passive scan (see below) |
| ASI09 Human-Agent Trust Exploitation | None: not observable by a passive scan (see below) |
| ASI10 Rogue Agents | None: not observable by a passive scan (see below) |
OWASP Agentic Skills Top 10, version 1.0-2026 (AST)
| Entry | Evidence the Inspector produces |
|---|---|
| AST01 Malicious Skills | None: not observable by a passive scan (see below) |
| AST02 Supply Chain Compromise | None: not observable by a passive scan (see below) |
| AST03 Over-Privileged Skills | Capability classification; Tool behaviour hints; Scope and permission evidence |
| AST04 Insecure Metadata | Description findings |
| AST05 Untrusted External Instructions | None: not observable by a passive scan (see below) |
| AST06 Weak Isolation | None: not observable by a passive scan (see below) |
| AST07 Update Drift | Definition pins and change since last scan |
| AST08 Poor Scanning | None: not observable by a passive scan (see below) |
| AST09 No Governance | Inventory and review packet |
| AST10 Cross-Platform Reuse | None: not observable by a passive scan (see below) |
Not observable by a passive scan
For these, a scan can only say that something exists, never what happens. They need telemetry or a control in the execution path, which is outside what this tool does.
Goal hijack and prompt injection at runtime
Depends on the content an agent reads while it runs.
Needs instead: Runtime inspection of inputs, plans and tool calls
What executes when a tool is called
A scan sees that an execute-style tool is declared, not what it runs or how it is sandboxed.
Needs instead: Sandboxing and execution telemetry
Memory and context poisoning
Happens inside the agent's stores and context.
Needs instead: Provenance and validation of memory writes
Cascading failures
Emerges from live interaction between agents and services.
Needs instead: Runtime monitoring, rate and blast-radius limits
Human-agent trust exploitation
Depends on how an agent talks to the people it works with.
Needs instead: Review of approval flows and user-facing behaviour
Rogue or drifting agent behaviour
Requires behaviour over time.
Needs instead: Behavioural baselines and the ability to stop an agent
Malicious content inside skill packages
The Inspector reads remote endpoints, not installable skill packages.
Needs instead: Package scanning and signing
Provenance of skill packages and dependencies
No package or dependency data is visible from a remote endpoint.
Needs instead: Transparency logs and dependency pinning
Remote content a skill loads at runtime
The Inspector does not follow or evaluate documents a tool says it will read.
Needs instead: Inventory and pinning of referenced sources
Process and container isolation
Isolation is a property of the host, not the endpoint.
Needs instead: Host-level controls
Quality of scanning itself
This is a property of a program's tooling, not of a target.
Needs instead: Multi-tool scanning and review
Skill reuse across agent platforms
Relates to skill packaging formats, not remote endpoints.
Needs instead: A common skill format and platform validation
How tools, tokens and inter-agent messages are used
A passive scan sees declarations and configuration, not tool calls, granted scopes or message contents.
Needs instead: Telemetry from the execution path
Sources: OWASP Top 10 for Agentic Applications 2026, OWASP Agentic Skills Top 10. ContextIQ is not affiliated with or endorsed by OWASP.