CXP: Adding Context Lifecycle, Provenance, and Governance to the AI Agent Protocol Stack
Rattachement africain : us. Niveau de preuve : code pays fourni par la source.
Le résumé fourni par la source
MCP connects agents to tools. A2A connects agents to agents. Neither tracks where context came from, who can see it, or how it was transformed. This paper introduces CXP (Context Exchange Protocol), a context lifecycle protocol whose INVOKE primitive handles both tool invocation and agent delegation alongside governance, provenance, and privacy scoping. CXP provides two transport bindings: CXP-Graph (GraphQL), where the graph-native transport matches the provenance DAG data model (1.4-2.0x faster than batched JSON-RPC), and JSON-RPC for backward-compatible MCP proxy mode requiring zero code changes. In experiments across 10 documents, three regulated industries (healthcare, finance, legal), and 50 agents per document (100 real Claude Sonnet API calls, 33,973 output tokens, plus 400 governance-scale agents), CXP enforced access control on every context object (510 COs, 500 provenance edges, 510 audit records), blocking unauthorized agents from accessing sensitive content. Four attacks specific to context-centric agent protocols are empirically demonstrated and mitigated (20/20 tests). The reference implementation (Python, 8,200+ lines, 150 tests), dual transport, proxy, and adversarial test suite are open-source under Apache 2.0.
Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.
Le contrôle bibliographique ouvert
Les institutions déclarées
Une affiliation ne permet pas de déduire la nationalité d’un auteur.