Trustworthy discovery requires audience-specific evidence, not one maximally detailed public card.
Why this question matters
A2A distinguishes public cards from authenticated extended cards. This creates room to reveal sensitive skills or endpoints only to authorized clients. The design problem is deciding which claims are necessary for selection, authorization, monitoring, and later accountability.
Over-disclosure gives attackers a capability map. Under-disclosure leaves clients unable to assess conflicts, operating boundaries, or required controls. Selective disclosure should therefore follow the decision being made and preserve a record of exactly what the relying party saw.
Signals worth observing
- A public card exposes internal URLs, private skills, or security details.
- Different audiences receive materially inconsistent identity claims.
- A client acts on a claim that cannot later be reproduced for audit.
Practical control direction
- Separate public capability summaries from authenticated evidence.
- Bind disclosures to audience, purpose, and expiration.
- Record disclosure versions without logging embedded secrets.
AgentCollusion lensRelationship monitoring needs enough shared context to explain trust without centralizing every confidential detail.Sources and further reading
Next field note: Push Notifications Add a Second Trust Channel


