Multi-agent LLM systems promise improved reasoning by collaboration of specialized agents through a sequence of API calls. This collaboration is also visible on the wire and opens new channels for leakage. Despite encrypted communication, a passive on-path observer can still learn the number, order, size and timing of the API calls. This metadata is generated by the system as a function of the input it processes. In adaptive multi-agent systems, the collaboration structure itself is chosen by the input, and that choice is visible in the traffic pattern. We coin this threat collaboration fingerprinting. Using MDAgents, a state-of-the-art medical multi-agent framework, we demonstrate on two datasets that a passive observer can recover the assigned case complexity and narrow a case’s diagnosis to a coarse clinical group, solely from collaboration metadata. A case’s clinical complexity determines the complexity of the collaboration. This dependency results in an inference-time privacy channel, unaddressed by existing content-level defenses. We thus argue that a multi-agent system’s observable network traffic must be treated as part of its confidentiality boundary.