Skip to main content

Insecure Inter-Agent Communication

Authenticate agent messages, bind them to one task and audience, validate content, and preserve actor and delegation evidence.

Threat

Inter-agent communication is insecure when a receiver cannot prove who sent a message, which subject and task it represents, which recipient may accept it, whether it is fresh and intact, or what authority accompanies it. Spoofed or replayed plans, results, and approvals can redirect an agent system.

Natural-language confidence is not authentication. A message that says "approved by Alice" is still untrusted data.

Bind message and authority

Authenticate the sending workload and intended receiver through a protected channel or signed message profile. Bind task identifier, subject, actor, audience, message type, sequence or nonce, issue time, expiry, and delegation reference. Validate structured fields before natural-language content reaches planning.

Separate information messages from authority grants. The receiver authorizes its own concrete action. Apply schema, size, content, attachment, and reference limits. Preserve correlation and parent-child relationships in evidence without forwarding broad bearer credentials.

Failure and residual risk

A valid agent can send a malicious or mistaken message. A shared queue identity can erase the sender. A replayed old approval can attach to a new task. A message can carry a link or tool result that triggers goal hijack. A broker can authenticate transport while allowing cross-tenant topic access.

End-to-end signatures help across intermediaries and add key, canonicalization, replay, and rotation complexity. They do not authorize the requested action.

Pomerium boundary

Pomerium can protect HTTP routes between agent services and preserve documented request identity. Message brokers, local processes, and agent protocols outside those routes need their own authentication and authorization. Each receiving agent or service owns message validation and action policy.

Evaluation checklist

  • Can the receiver verify sender, subject, actor, audience, task, freshness, and integrity?
  • Are information, request, result, approval, and authority messages distinct?
  • Does the receiver authorize the concrete action from current state?
  • Are cross-tenant topics, queues, callbacks, and attachments isolated?
  • Can spoof, replay, reorder, wrong-audience, and compromised-sender tests fail safely?

Sources and further reading

Keep learning

Agentic AccessAuthorization and Policy

Delegation Chain

Preserve the human actor, agent, service, tool, target, authority, and constraints through every delegated access step.

Learn this term
Agentic AccessIdentity and Authentication

Identity Propagation

Identity propagation carries verified information about the originating principal and, when needed, the acting service across request boundaries.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo