Problem
An A2A peer's task can write to the knowledge base, and no capability covers that.
- The orchestrator routes research requests to
librarian_assistant.research_query(request): agents/agent_orchestration/agent_execution.py, AgentType.RESEARCH.
research_query auto-stores "quality" web content into the KB by default: auto_store_quality defaults to True (agents/librarian_assistant.py:61) and is applied when the caller passes nothing (:501). The write happens through store_in_knowledge_base (:311, :402).
- The orchestrator passes nothing. So a peer whose query steers the research also chooses content that is written into the knowledge base other users read.
#16957's routing gate requires QUERY_MEMORY for the research agent, a read capability, so a STANDARD peer still reaches this write. The A2A capability matrix has no write capability at all.
Why it matters
The knowledge base is shared and trusted input for retrieval. A peer-chosen write is a poisoning path, and the operator cannot see that a peer caused it.
Acceptance criteria
Problem
An A2A peer's task can write to the knowledge base, and no capability covers that.
librarian_assistant.research_query(request):agents/agent_orchestration/agent_execution.py,AgentType.RESEARCH.research_queryauto-stores "quality" web content into the KB by default:auto_store_qualitydefaults toTrue(agents/librarian_assistant.py:61) and is applied when the caller passes nothing (:501). The write happens throughstore_in_knowledge_base(:311,:402).#16957's routing gate requires
QUERY_MEMORYfor the research agent, a read capability, so aSTANDARDpeer still reaches this write. The A2A capability matrix has no write capability at all.Why it matters
The knowledge base is shared and trusted input for retrieval. A peer-chosen write is a poisoning path, and the operator cannot see that a peer caused it.
Acceptance criteria