[Bug]: AgentCard REQUIRED fields are never validated
Maintainers usually reply within 2 days
Nobody has claimed this yet.
Assessment
This issue has not been assessed yet.
Description
What happened?
AgentCard marks 8 fields field_behavior = REQUIRED (https://github.com/a2aproject/A2A/blob/main/specification/a2a.proto#L362-L399): name, description, supported_interfaces, version, capabilities, default_input_modes, default_output_modes, skills.
Nothing in the SDK checks them. proto3 has no required keyword and the annotation is inert metadata, so an empty card is constructible and travels the whole pipeline unchallenged:
AgentCard() # -> served as HTTP 200 with body {}
None of the methods that accept a card validate it:
- create_agent_card_routes(agent_card=...)
- DefaultRequestHandler(agent_card=..., extended_agent_card=...) and on_get_extended_agent_card — validates the request, never the returned card
- agent_card_to_dict(card)
Correct fix: call the existing validate_proto_required_fields where the card is passed. This would introduce breaking changes for clients that rely on non-spec compliant agent card.
Suggested first step: log a warning when validation fails rather than raising, which is non-breaking and surfaces the problem to the user, with enforcement by default deferred to a major version.
Relevant log output
Code of Conduct
- I agree to follow this project's Code of Conduct
- Dominant language
- Python
- Stars
- 2.2k
- Forks
- 499
- Avg merge
- 3d 15h
- Merged PRs (30d)
- 28
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from a2aproject/a2a-python
-
Create push notification config returns no id on database-backed storesPossibly taken @ConnorMoss02 claimed this 4 days ago. Opencomponent: server
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
a2aproject/a2a-python#1237 · 2 comments · 1 assignee ·
Maintainers usually reply within 2 days
-
maintainers-only
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
a2aproject/a2a-python#805 · 1 comment ·
Maintainers usually reply within 2 days
-
[Feat]: Change Httpx to Httpx2Possibly taken @rohityan claimed this 1 day ago. Opencomponent: client status: needs review
a2aproject/a2a-python#1288 · 2 comments · 1 assignee ·
Maintainers usually reply within 2 days
-
[Bug]: Streaming follow-up on an existing task does not begin with a Task; enqueuing the current task drops the follow-up message from historyPossibly taken @rohityan claimed this 2 days ago. Opencomponent: server status:awaiting response
a2aproject/a2a-python#1285 · 1 comment · 1 assignee ·
Maintainers usually reply within 2 days
-
component: core
a2aproject/a2a-python#1278 · 9 comments · 1 assignee ·
Maintainers usually reply within 2 days
All issues in a2aproject/a2a-python
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
raullenchai/Rapid-MLX#4042 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
LearningCircuit/local-deep-research#7067 ·
Maintainers usually reply within 1 day
-
#bug
Difficulty 1/5 Under an hour Newbie friendliness 92/100
apache/superset#44923 · 1 comment ·
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
lawndoc/stack-back#123 ·