A new security analysis of Google's Agent Payments Protocol (AP2) has identified significant vulnerabilities, even in its updated v0.2 version. The research highlights that while signed mandates protect transaction data post-signing, the protocol remains susceptible to manipulation before authorization. This includes attacks via Agent-to-Agent Protocol (A2A) messages and Model Context Protocol (MCP) tool calls, which can alter a transaction's context and potentially deviate from user intent. The study developed a testbed and proof-of-concept demonstrations for eight high-risk threats. AI
IMPACT Highlights critical security flaws in LLM payment protocols, potentially impacting secure AI agent transactions.
RANK_REASON Academic paper detailing security analysis of a specific protocol. [lever_c_demoted from research: ic=1 ai=1.0]
- Agent Payments Protocol (AP2)
- Agent-to-Agent Protocol (A2A)
- Artificial Intelligence Vulnerability Scoring System (AIVSS)
- Checkout and Payment Mandates
- Maestro
- Model Context Protocol (MCP)
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →