Research · curated 1 Sep 2026
Beyond the Mandate: A Systematic Security Analysis of the Agent Payments Protocol (AP2)
First reported arxiv.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
AP2 governs autonomous agent payments on users' behalf, so weaknesses in its pre-authorization context — exploitable via prompt injection and MCP/A2A manipulation — expose a direct path to fraudulent financial transactions in emerging agentic commerce.
Researchers from Ben-Gurion University and Intuit present a systematic security analysis of Google's Agent Payments Protocol (AP2) v0.2, which lets LLM-driven shopping agents authorize and execute payments. Using the MAESTRO framework they model threat actors, attack surfaces, and adversary capabilities, cataloging 48 threats across five attack families, scoring them with AIVSS, building a testbed across five deployment architectures, and developing proof-of-concept demonstrations for eight High-risk threats plus a deployment-aware scanner. Their key finding: valid mandate signatures alone do not guarantee an agent-mediated transaction reflects user intent when pre-authorization context (A2A messages, MCP tool calls) is manipulated.