Privacy Threats in MCP and A2A: Agentic AI Communication Protocols

A LINDDUN-Based Privacy Threat Analysis of MCP and A2A in a Financial Fraud Detection Context

Master Thesis (2026)
Author(s)

W.H.J. Elshout (TU Delft - Technology, Policy and Management)

Contributor(s)

G.A. de Reuver – Graduation committee member (TU Delft - Technology, Policy and Management)

M.E. Warnier – Graduation committee member (TU Delft - Technology, Policy and Management)

Valentijn Bieger – Mentor (Avanade)

Faculty
Technology, Policy and Management
More Info
expand_more
Publication Year
2026
Language
English
Coordinates
52.0062916, 4.3599139
Graduation Date
22-06-2026
Awarding Institution
Delft University of Technology
Programme
Complex Systems Engineering and Management (CoSEM)
Sponsors
Avanade
Faculty
Technology, Policy and Management
Downloads counter
34
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract


The Model Context Protocol (MCP) and the Agent-to-Agent (A2A) protocol have quickly become the de facto standards for connecting large-language-model agents to external tools and to one another across organisational boundaries. Their security has begun to receive attention, but their privacy implications, what personal data flows where and under what controls, remain largely unexamined, even as the protocols are adopted in sensitive domains where the people whose data is processed are not parties to the exchange.

This thesis presents a data-subject-centred privacy threat analysis of MCP and A2A using the LINDDUN methodology, applied to a representative financial fraud-detection use case modelled as a multi-agent system. A data-flow model is elicited, threats are systematically derived across the LINDDUN categories, and the findings are validated through interviews with seven domain experts and discussed with a co-author of the LINDDUN framework.

The analysis identifies eight privacy threats across five LINDDUN categories. The most severe arise not from misconfiguration or attack but because the protocols operate as designed: a persistent session identifier enables linkability and cross-store aggregation, unconstrained context-passing exposes identifiable data across organisational boundaries, and the bilateral task record creates a non-repudiable trace. The threats range from protocol-inherent to use-case-inherent, and three form a cross-protocol chain in which exposure compounds as data crosses the boundary between the two protocols; the trust boundary, more than the protocol choice, amplifies severity.

This is the first privacy analysis of MCP and A2A framed from the data subject's perspective. It shows that privacy here is non-compositional, so per-flow assessments miss risks that emerge only when flows combine. Because the decisive design choices are fixed at the protocol layer, the thesis argues that effective privacy governance must engage protocol designers and standards bodies, not deploying organisations alone.

Files

License info not available