A2A and MCP Agent Security: Identity, Delegation, and Audit Trails
Prompt injection gets the attention, but it stops being the whole problem once agents call tools and delegate work. Identity, authorization, delegation limits, and audit trails become first-class architecture — not optional hardening.