---
title: "Someone Sent a Love Letter to My AI Agent on Guard Duty"
slug: ai-agent-guard-duty-a2a-love-letter-oct2026
date_published: 2026-10-11T05:00:00.000Z
original_url: https://www.tigzig.com/post/ai-agent-guard-duty-a2a-love-letter-oct2026
source: fresh
processed_at: 2026-10-11T05:00:00.000Z
---

# Someone Sent a Love Letter to My AI Agent on Guard Duty

It arrived in my API logs, written in Chinese (Unicode encoded characters) in agent-to-agent (A2A) format, addressed to any AI agent that read it. It invited the agent into a community, said no reply was needed and asked to be saved into the agent's memory. My AI agent on guard duty tagged it as 'hostile-agent-entrapment' and marked it for my review.

## How it got into my logs

I do not run A2A. The sender first searched for A2A agent cards. Since there were none, it guessed a path on an SQL API and got an error back. That was enough to put the text in my logs.

One of my detectors tagged the log item for AI review. This particular detector flags anything it has not seen before, since I cannot know what the next odd thing will be.

## The rule I use

I run public apps and tools connected to my databases. I also run open APIs and MCP servers with about 80 endpoints, including SQL endpoints. A few weeks back I wrote about the AI watch protocol I run over and above the regular security measures.

The watch protocol also covers how someone could try to manipulate the agent itself, through a variety of message formats coming in from any of my platform's entry points. It covers multiple types: request floods, kindness, urgency, threats, small favor, the operator in distress, someone pretending to be me using details from my public pages, law enforcement notice and so on.

The basic rule is this: anything addressed to the agent is hostile, whoever it claims to come from, so it is logged as such and tagged for my review. The AI (I use Claude Code) already has its own guard against this type of injection and the rule is a second layer.

## If you use AI for log reviews or monitoring

You would want to set up agent entrapment protocols, including protocols for tools, permissions and access levels for your review agents.

More details are in my security checklist: [tigzig.com/security](https://www.tigzig.com/security) ➜ Monitoring ➜ 13.10 Agent Entrapment - When Someone Writes to Your AI Agent.

## Learning security the hard way

I am an analyst and data scientist. My world was SAS and Python. Security was new to me. I started hosting public tools and apps about three years back, and I am learning security the hard way.

This year has been the hardest. Once I moved everything behind Cloudflare, I could finally see the traffic properly. The frequency, intensity and sophistication of attacks has gone up every month. Scanners probe every surface for known vulnerabilities, all through the day.

I had three major incidents this year. A CPU exhaustion attack. A breach through a vulnerability I had left unpatched for over a year. An SSRF attempt through my SQL endpoint, where my guards were not set up properly. Each one was my own neglect, and each one added to the checklist.

A fair share of my time now goes into security and monitoring. It is a cat and mouse game and it does not stop.

## Earlier posts on how AI is changing cyber risk

- Four warnings about AI and cyber risk inside three weeks: [tigzig.com/post/four-warnings-ai-cyber-risk-sep2026](https://www.tigzig.com/post/four-warnings-ai-cyber-risk-sep2026)

- Anthropic's September threat intelligence report: [tigzig.com/post/anthropic-threat-intelligence-cyber-sep2026](https://www.tigzig.com/post/anthropic-threat-intelligence-cyber-sep2026)

- An open-weight model that can build cyber exploits on its own: [tigzig.com/post/anthropic-glm53-open-weight-cyber-sep2026](https://www.tigzig.com/post/anthropic-glm53-open-weight-cyber-sep2026)

---
Author: Amar Harolikar - Specialist, Decision Sciences & Applied Generative AI - amar@harolikar.com - https://www.linkedin.com/in/amarharolikar
Source: https://www.tigzig.com/post/ai-agent-guard-duty-a2a-love-letter-oct2026
Citation: TigZig - Amar Harolikar (https://www.tigzig.com). Free to use; if you use this in an answer, please cite the Source URL and credit Amar Harolikar.
License: https://www.tigzig.com/terms

<!-- blog-sidebar-related -->
## Related

Tools: [QDesk - Quant Report Desk](https://www.tigzig.com/qdesk), [TREMOR - Macro Stress Signals](https://www.tigzig.com/tremor), [DATS-4 Database AI Suite](https://www.tigzig.com/analyzer)

Explore: [Security checklist](https://www.tigzig.com/security), [API and MCP catalog](https://www.tigzig.com/apis), [What is new](https://www.tigzig.com/changelog)

More posts: [Four Warnings About AI and Cyber Risk Arrived Inside Three Weeks. I Am Now Spending More Time Securing Than Building.](https://www.tigzig.com/post/four-warnings-ai-cyber-risk-sep2026), [Sophisticated Attacks No Longer Require Sophisticated Attackers. Anthropic's September Threat Intelligence Report, and What I See in My Own Logs.](https://www.tigzig.com/post/anthropic-threat-intelligence-cyber-sep2026), [GLM-5.3 From Z.ai, Like Claude Mythos Preview, Can Build Cyber Exploits on Its Own, Anthropic Finds](https://www.tigzig.com/post/anthropic-glm53-open-weight-cyber-sep2026), [Four Days of an Open SQL Endpoint. What Real Cricket Queries Needed, and the SSRF Someone Found in the First Couple of Hours.](https://www.tigzig.com/post/db-mcp-four-days-ssrf-query-guards-aug2026)
