A2A BridgeSAFE
A mcp server that bridges the Model Context Protocol (MCP) with the Agent-to-Agent (A2A) protocol, enabling MCP-compatible AI assistants (like Claude) to seamlessly interact with A2A agents.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://opensource.org/licenses/Apache-2.0) [](https://smithery.ai/server/@GongRzhe/A2A-MCP-Server)
A mcp server that bridges the Model Context Protocol (MCP) with the Agent-to-Agent (A2A) protocol, enabling MCP-compatible AI assistants (like Claude) to seamlessly interact with A2A agents.
Overview
This project serves as an integration layer between two cutting-edge AI agent protocols:
- Model Context Protocol (MCP): Developed by Anthropic, MCP allows AI assistants to connect to external tools and data sources. It standardizes how AI applications and large language models connect to external resources in a secure, composable way.
- Agent-to-Agent Protocol (A2A): Developed by Google, A2A enables communication and interoperability between different AI agents through a standardized JSON-RPC interface.
By bridging these protocols, this server allows MCP clients (like Claude) to discover, register, communicate with, and manage tasks on A2A agents through a unified interface.
Demo
1, Run The Currency Agent in A2A Sample
also support cloud deployed Agent
2, Use Claude to Register the Currency Agent
3, Use Claude to Send a task to the Currency Agent and get the result
Features
- Agent Management
- Register A2A agents with the bridge server
- List all registered agents
- Unregister agents when no longer needed
- Communication
- Send messages to A2A agents and receive responses
- Stream responses from A2A agents in real-time
- Task Management
- Track which A2A agent handles which task
- Retrieve task results us
6340d0b1550bOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add a2a_mcp_server -- uvx a2a_mcp_server
{
"mcpServers": {
"a2a_mcp_server": {
"command": "uvx",
"args": [
"a2a_mcp_server"
]
}
}
}Exposed tools (7)
5 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
cancel_task | read | |
get_task_result | read | |
list_agents | read | |
register_agent | read | |
send_message | write | |
send_message_stream | write | |
unregister_agent | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
- Use the URL: `http://127.0.0.1:8000/mcp`
- Add a new MCP Server with URL: `http://127.0.0.1:8000/mcp`
- Add a new MCP connection with URL: `http://127.0.0.1:8000/mcp`
httpx, httpx-sse, jwcrypto, pydantic, pyjwt, sse-starlette, starlette, typing-extensions
Gates applied: no_behavioural_pass.
6340d0b1550bfull audit observations/trust-audit/mcp-server/gongrzhe__a2a-bridge.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 6340d0b1550b | SAFE | B | 89 | first audit |
Questions
What is the A2A Bridge MCP server?
A mcp server that bridges the Model Context Protocol (MCP) with the Agent-to-Agent (A2A) protocol, enabling MCP-compatible AI assistants (like Claude) to seamlessly interact with A2A agents.
What tools does A2A Bridge expose?
7 in total: 5 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is A2A Bridge safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does A2A Bridge need?
No credential environment variables were found in its source, so it appears to need none.
How does A2A Bridge run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as a2a_mcp_server.
How current is this page?
The grade is for one exact copy of the source (6340d0b1550b), read on 2026-10-07. The repository is watched and re-audited when it changes.