Threat
Inter-agent communication is insecure when a receiver cannot prove who sent a message, which subject and task it represents, which recipient may accept it, whether it is fresh and intact, or what authority accompanies it. Spoofed or replayed plans, results, and approvals can redirect an agent system.
Natural-language confidence is not authentication. A message that says "approved by Alice" is still untrusted data.
Bind message and authority
Authenticate the sending workload and intended receiver through a protected channel or signed message profile. Bind task identifier, subject, actor, audience, message type, sequence or nonce, issue time, expiry, and delegation reference. Validate structured fields before natural-language content reaches planning.
Separate information messages from authority grants. The receiver authorizes its own concrete action. Apply schema, size, content, attachment, and reference limits. Preserve correlation and parent-child relationships in evidence without forwarding broad bearer credentials.
Failure and residual risk
A valid agent can send a malicious or mistaken message. A shared queue identity can erase the sender. A replayed old approval can attach to a new task. A message can carry a link or tool result that triggers goal hijack. A broker can authenticate transport while allowing cross-tenant topic access.
End-to-end signatures help across intermediaries and add key, canonicalization, replay, and rotation complexity. They do not authorize the requested action.
Pomerium boundary
Pomerium can protect HTTP routes between agent services and preserve documented request identity. Message brokers, local processes, and agent protocols outside those routes need their own authentication and authorization. Each receiving agent or service owns message validation and action policy.
Evaluation checklist
- Can the receiver verify sender, subject, actor, audience, task, freshness, and integrity?
- Are information, request, result, approval, and authority messages distinct?
- Does the receiver authorize the concrete action from current state?
- Are cross-tenant topics, queues, callbacks, and attachments isolated?
- Can spoof, replay, reorder, wrong-audience, and compromised-sender tests fail safely?
