AgentRFC: Security Design Principles and Conformance Testing for Agent Protocols
Shenghan Zheng, Qifan Zhang

TL;DR
This paper introduces a comprehensive security framework for AI agent protocols, including a layered architectural model, formal security principles, and a conformance testing tool, to ensure protocol security and correct implementation.
Contribution
It presents a novel 6-layer architectural model, formal security principles in TLA+, and a conformance checker for agent protocols, addressing security gaps in protocol composition.
Findings
Identified security gaps in credential lifecycle and consent enforcement.
Formal models reveal cross-protocol composition vulnerabilities.
Preliminary results show recurrent security issues in agent protocols.
Abstract
AI agent protocols -- including MCP, A2A, ANP, and ACP -- enable autonomous agents to discover capabilities, delegate tasks, and compose services across trust boundaries. Despite massive deployment (MCP alone has 97M+ monthly SDK downloads), no systematic security framework for these protocols exists. We present three contributions. First, the Agent Protocol Stack, a 6-layer architectural model that defines what a complete agent protocol must specify at each layer -- analogous to ITU-T X.800 for the OSI stack. Second, the Agent-Agnostic Security Model, 11 security principles formalized as TLA+ invariants, each tagged with a property taxonomy (spec-mandated, spec-recommended, aasm-hardening, aps-completeness) that distinguishes protocol non-conformance from framework-imposed security requirements. Third, AgentConform, a two-phase conformance checker that (i)extracts normative clauses…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsMobile Agent-Based Network Management · Advanced Authentication Protocols Security · Access Control and Trust
