CrawlCheck

Glossary · area 16 of 19

Agents and protocols

How autonomous agents plan, remember, call tools and talk to each other, including MCP and A2A, and where each step can go wrong.

42 terms. Each opens its own page with what it can and cannot support, how the scanner measures it, and where it comes up in the guides.

42terms in this area
0with a live finding rate

AI agent

Software that uses a model plus tools, state, and control logic to pursue a task across multiple steps. The label does not imply autonomy, reliability, or legal agency.

Agent loop

The repeated cycle of observing state, choosing an action, executing it, and evaluating the result. Without limits it can repeat errors, consume budgets, or act beyond the original intent.

Planner

The component that decomposes a goal into proposed steps or dependencies. A coherent plan is not evidence that the steps are feasible, authorized, or complete.

Executor

The component that performs selected tool calls or actions. Separating it from planning allows policy checks but does not guarantee they are correctly implemented.

Agent memory

Stored information carried across steps, sessions, or users to support continuity. It introduces retention, privacy, staleness, and incorrect-association risks.

Working memory

Temporary task state kept within the active context or run. It is constrained by context and can disappear during compaction, retries, or handoffs.

Long-term memory

State persisted beyond one interaction for later retrieval. Persistence does not make a memory accurate, relevant, current, or appropriate to expose.

Episodic memory

Stored records of prior events, interactions, or runs. Recalling an episode can guide behavior while importing a past error into a new context.

Semantic memory

Stored facts or generalized knowledge extracted from earlier material. It removes event detail and may lose when, where, or how a claim was established.

Agent orchestration

Coordinating models, tools, agents, approvals, and state through a workflow. More components expand capability and the number of failure boundaries.

Multi-agent system

A system in which several agents communicate or divide work. Agreement among agents is not independent corroboration when they share models, prompts, or sources.

Agent handoff

Transferring control and task context from one agent to another. Missing constraints or provenance at the boundary can change the task silently.

Delegation

Assigning another agent responsibility for a task or subtask. The delegating agent still needs to validate authority, inputs, outputs, and side effects.

Tool result

Data returned after an external operation invoked by a model or workflow. It should be treated as untrusted input unless the source and schema are verified.

Tool schema

The machine-readable definition of a tool’s parameters and result shape. It constrains syntax but not business rules, permissions, or safe combinations of values.

Tool description

Natural-language guidance telling a model when and why to use a tool. Small wording changes can alter selection, making descriptions part of application behavior.

Tool selection

The decision to answer directly or invoke one or more available functions. A correct tool can still be called with the wrong arguments or at the wrong time.

Tool permission

A policy determining which actions an agent may invoke in a context. Exposure in a schema is not the same as authorization to execute.

Human-in-the-loop

A workflow requiring human review, input, or approval at specified points. It reduces some risks only if the reviewer receives adequate context and can meaningfully refuse.

Human-on-the-loop

Human supervision of mostly autonomous execution with the ability to intervene. Oversight after rapid or irreversible actions may be nominal rather than effective.

Approval gate

A control that pauses execution before a consequential step. It should bind the approved parameters and target; approving a vague plan is not approving every resulting action.

Agent sandbox

An isolated environment restricting code, network, files, credentials, or system calls. Isolation limits impact but is only as strong as its escape boundaries and configuration.

Agent identity

The verifiable principal on whose behalf an agent connects or acts. A product name in a request is not authentication.

Agent authorization

The permissions granted to an authenticated agent or delegated user. Identity answers who; authorization answers what that principal may do.

Agent discovery

Finding machine-readable descriptions of available agents and capabilities. Discovery exposes claims that clients must still validate before delegation.

Capability negotiation

Client and server agreeing on supported versions, modalities, streaming, or interaction features. It prevents incompatible use but does not assess output quality.

MCP server

A program exposing resources, prompts, tools, or related capabilities through Model Context Protocol. Availability through MCP does not make its data trusted or its actions safe.

MCP client

The protocol component maintaining a connection between a host application and an MCP server. It transports capabilities and messages but need not make model decisions itself.

MCP host

The user-facing AI application coordinating one or more MCP clients. Host policy determines which server capabilities are exposed to the model or user.

MCP resource

Context or data a server makes available for a user or model to read. A resource is not necessarily static, public, authoritative, or side-effect free.

MCP prompt

A server-provided message template or workflow intended for explicit user selection. It supplies instructions, not an independently executable capability.

MCP tool

A callable function an MCP server allows a model to request. Tool metadata describes expected use; the server remains responsible for validation and access control.

MCP transport

The communication mechanism carrying MCP protocol messages between components. Transport security and application authorization are separate requirements.

JSON-RPC

A JSON-based remote procedure call format used by protocols including MCP. Well-formed messages do not authenticate sender, authorize methods, or encrypt transport.

A2A protocol

A protocol for a client agent to discover and exchange task-related messages with a remote agent. It complements tool protocols but does not make autonomous delegation trustworthy.

A2A client

The application or agent initiating requests to an A2A server for a user or another system. It must decide whether the remote agent is suitable and authorized.

A2A server

A remote agent exposing an A2A-compatible interface for tasks and responses. Protocol compliance does not establish competence or honesty.

Agent skill

A capability unit advertised by an agent with identifiers, descriptions, examples, and supported modes. It is a declared ability, not an independently tested certification.

Agent task

A stateful unit of delegated work exchanged through an agent protocol. Task completion status does not prove that the result is correct or accepted by the user.

Agent artifact

A file, structured object, or other output produced during an agent task. It should retain provenance and content type rather than relying only on the surrounding conversation.

WebMCP

A proposal for a web page to expose tools to a browser-based agent through a small script bridge, so the agent can act on the page's functions rather than scraping its markup. It runs client-side, so it is invisible to a server-side scanner and to any agent that does not execute scripts.

A2A

Agent-to-Agent, a protocol for one agent to discover another's capabilities through an agent card and delegate tasks to it over HTTP. It standardises the handshake between agents, not what they may do; an agent card is a claim about capability that a caller still has to test.

← Measurement and evaluation  ·  Security and privacy →

All 668 terms across 19 areas.