AI agent
Software that uses a model plus tools, state, and control logic to pursue a task across multiple steps. The label does not imply autonomy, reliability, or legal agency.
Glossary · area 16 of 19
How autonomous agents plan, remember, call tools and talk to each other, including MCP and A2A, and where each step can go wrong.
42 terms. Each opens its own page with what it can and cannot support, how the scanner measures it, and where it comes up in the guides.
Software that uses a model plus tools, state, and control logic to pursue a task across multiple steps. The label does not imply autonomy, reliability, or legal agency.
The repeated cycle of observing state, choosing an action, executing it, and evaluating the result. Without limits it can repeat errors, consume budgets, or act beyond the original intent.
The component that decomposes a goal into proposed steps or dependencies. A coherent plan is not evidence that the steps are feasible, authorized, or complete.
The component that performs selected tool calls or actions. Separating it from planning allows policy checks but does not guarantee they are correctly implemented.
Stored information carried across steps, sessions, or users to support continuity. It introduces retention, privacy, staleness, and incorrect-association risks.
Temporary task state kept within the active context or run. It is constrained by context and can disappear during compaction, retries, or handoffs.
State persisted beyond one interaction for later retrieval. Persistence does not make a memory accurate, relevant, current, or appropriate to expose.
Stored records of prior events, interactions, or runs. Recalling an episode can guide behavior while importing a past error into a new context.
Stored facts or generalized knowledge extracted from earlier material. It removes event detail and may lose when, where, or how a claim was established.
Coordinating models, tools, agents, approvals, and state through a workflow. More components expand capability and the number of failure boundaries.
A system in which several agents communicate or divide work. Agreement among agents is not independent corroboration when they share models, prompts, or sources.
Transferring control and task context from one agent to another. Missing constraints or provenance at the boundary can change the task silently.
Assigning another agent responsibility for a task or subtask. The delegating agent still needs to validate authority, inputs, outputs, and side effects.
Data returned after an external operation invoked by a model or workflow. It should be treated as untrusted input unless the source and schema are verified.
The machine-readable definition of a tool’s parameters and result shape. It constrains syntax but not business rules, permissions, or safe combinations of values.
Natural-language guidance telling a model when and why to use a tool. Small wording changes can alter selection, making descriptions part of application behavior.
The decision to answer directly or invoke one or more available functions. A correct tool can still be called with the wrong arguments or at the wrong time.
A policy determining which actions an agent may invoke in a context. Exposure in a schema is not the same as authorization to execute.
A workflow requiring human review, input, or approval at specified points. It reduces some risks only if the reviewer receives adequate context and can meaningfully refuse.
Human supervision of mostly autonomous execution with the ability to intervene. Oversight after rapid or irreversible actions may be nominal rather than effective.
A control that pauses execution before a consequential step. It should bind the approved parameters and target; approving a vague plan is not approving every resulting action.
An isolated environment restricting code, network, files, credentials, or system calls. Isolation limits impact but is only as strong as its escape boundaries and configuration.
The verifiable principal on whose behalf an agent connects or acts. A product name in a request is not authentication.
The permissions granted to an authenticated agent or delegated user. Identity answers who; authorization answers what that principal may do.
Finding machine-readable descriptions of available agents and capabilities. Discovery exposes claims that clients must still validate before delegation.
Client and server agreeing on supported versions, modalities, streaming, or interaction features. It prevents incompatible use but does not assess output quality.
A program exposing resources, prompts, tools, or related capabilities through Model Context Protocol. Availability through MCP does not make its data trusted or its actions safe.
The protocol component maintaining a connection between a host application and an MCP server. It transports capabilities and messages but need not make model decisions itself.
The user-facing AI application coordinating one or more MCP clients. Host policy determines which server capabilities are exposed to the model or user.
Context or data a server makes available for a user or model to read. A resource is not necessarily static, public, authoritative, or side-effect free.
A server-provided message template or workflow intended for explicit user selection. It supplies instructions, not an independently executable capability.
A callable function an MCP server allows a model to request. Tool metadata describes expected use; the server remains responsible for validation and access control.
The communication mechanism carrying MCP protocol messages between components. Transport security and application authorization are separate requirements.
A JSON-based remote procedure call format used by protocols including MCP. Well-formed messages do not authenticate sender, authorize methods, or encrypt transport.
A protocol for a client agent to discover and exchange task-related messages with a remote agent. It complements tool protocols but does not make autonomous delegation trustworthy.
The application or agent initiating requests to an A2A server for a user or another system. It must decide whether the remote agent is suitable and authorized.
A remote agent exposing an A2A-compatible interface for tasks and responses. Protocol compliance does not establish competence or honesty.
A capability unit advertised by an agent with identifiers, descriptions, examples, and supported modes. It is a declared ability, not an independently tested certification.
A stateful unit of delegated work exchanged through an agent protocol. Task completion status does not prove that the result is correct or accepted by the user.
A file, structured object, or other output produced during an agent task. It should retain provenance and content type rather than relying only on the surrounding conversation.
A proposal for a web page to expose tools to a browser-based agent through a small script bridge, so the agent can act on the page's functions rather than scraping its markup. It runs client-side, so it is invisible to a server-side scanner and to any agent that does not execute scripts.
Agent-to-Agent, a protocol for one agent to discover another's capabilities through an agent card and delegate tasks to it over HTTP. It standardises the handshake between agents, not what they may do; an agent card is a claim about capability that a caller still has to test.