You cannot look their agent up anywhere.
No trusted directory exists. Partners must exchange addresses manually, and keeping those lists current becomes impossible at scale.
Anything can say it is your agent.
An agent ID is just text anyone can type. Receivers have no way to verify who actually sent the message.
It carries every key it might need, the whole time.
Agents hold all credentials upfront because no one can approve each request in real-time. One breach exposes everything.
It hands on everything it was given.
Credentials cannot be scoped to specific tasks. Each handoff accumulates more permissions than necessary.








