DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Loopjacking in A2A Implementations: Hijacking Human-in-the-Loop Approvals

Quality: 8/10 Relevance: 9/10

Summary

An in-depth field note examining how an A2A task update can hijack a human-in-the-loop approval, replacing a pending operation with a different one before execution. It explains the distinction between coordination and approval records, the spec clarifications (7.6.4), and outlines defenses like binding the approved action to the exact operation and performing atomic checks, supported by an in-memory LangGraph test and evidence.

🚀 Service construit par Johan Denoyer