Atlas / MCP servers / gongrzhe / A2A Bridge

A2A BridgeSAFE

mcp/gongrzhe/a2a-bridge

A mcp server that bridges the Model Context Protocol (MCP) with the Agent-to-Agent (A2A) protocol, enabling MCP-compatible AI assistants (like Claude) to seamlessly interact with A2A agents.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
7 5r · 2w · 0d
Transport
sse · stdio · streamable-http
License
Apache-2.0
Stars
147
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://opensource.org/licenses/Apache-2.0) [](https://smithery.ai/server/@GongRzhe/A2A-MCP-Server)

A mcp server that bridges the Model Context Protocol (MCP) with the Agent-to-Agent (A2A) protocol, enabling MCP-compatible AI assistants (like Claude) to seamlessly interact with A2A agents.

Overview

This project serves as an integration layer between two cutting-edge AI agent protocols:

  • Model Context Protocol (MCP): Developed by Anthropic, MCP allows AI assistants to connect to external tools and data sources. It standardizes how AI applications and large language models connect to external resources in a secure, composable way.
  • Agent-to-Agent Protocol (A2A): Developed by Google, A2A enables communication and interoperability between different AI agents through a standardized JSON-RPC interface.

By bridging these protocols, this server allows MCP clients (like Claude) to discover, register, communicate with, and manage tasks on A2A agents through a unified interface.

Demo

1, Run The Currency Agent in A2A Sample

also support cloud deployed Agent

2, Use Claude to Register the Currency Agent

3, Use Claude to Send a task to the Currency Agent and get the result

Features

  • Agent Management
  • Register A2A agents with the bridge server
  • List all registered agents
  • Unregister agents when no longer needed
  • Communication
  • Send messages to A2A agents and receive responses
  • Stream responses from A2A agents in real-time
  • Task Management
  • Track which A2A agent handles which task
  • Retrieve task results us
Read from source at commit 6340d0b1550bOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add a2a_mcp_server -- uvx a2a_mcp_server
claude-desktop
{
  "mcpServers": {
    "a2a_mcp_server": {
      "command": "uvx",
      "args": [
        "a2a_mcp_server"
      ]
    }
  }
}
03

Exposed tools (7)

5 read · 2 write · 0 destructive.

ToolRiskDescription
cancel_taskread
get_task_resultread
list_agentsread
register_agentread
send_messagewrite
send_message_streamwrite
unregister_agentread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (4)

LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:246
- Use the URL: `http://127.0.0.1:8000/mcp`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:278
- Add a new MCP Server with URL: `http://127.0.0.1:8000/mcp`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:293
- Add a new MCP connection with URL: `http://127.0.0.1:8000/mcp`
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
httpx, httpx-sse, jwcrypto, pydantic, pyjwt, sse-starlette, starlette, typing-extensions
Why it matters. 10 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 6340d0b1550bfull audit observations/trust-audit/mcp-server/gongrzhe__a2a-bridge.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-076340d0b1550bSAFEB89first audit
06

Questions

What is the A2A Bridge MCP server?

A mcp server that bridges the Model Context Protocol (MCP) with the Agent-to-Agent (A2A) protocol, enabling MCP-compatible AI assistants (like Claude) to seamlessly interact with A2A agents.

What tools does A2A Bridge expose?

7 in total: 5 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is A2A Bridge safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does A2A Bridge need?

No credential environment variables were found in its source, so it appears to need none.

How does A2A Bridge run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as a2a_mcp_server.

How current is this page?

The grade is for one exact copy of the source (6340d0b1550b), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement