It currently ships 22 stable attack cases, and the latest work has been less about adding more IDs and more about tightening one boundary I keep coming back to: does the original authorization still survive after an agent handoff or protocol translation?
A request can be perfectly valid structurally and still become broader by the time it reaches the downstream tool.
I’ve been turning those cases into deterministic A2A → MCP fixtures and discussing the boundary in a few current A2A/MCP threads. One of those conversations has already turned into a deeper discussion around context binding and the final authorization point before a downstream effect.
The next thing I care about most is real usage rather than adding more surface area: CI runs, concrete handoff cases, and feedback from people actually building agent-to-agent or agent-to-tool workflows.
If you’re working with A2A, MCP, or another agent handoff boundary, I’d genuinely be interested in the failure case you’re most worried about.