a2a-protocol
Pass
Audited by Gen Agent Trust Hub on Jul 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a technical guide for inter-agent communication and discovery. It does not perform any automated actions or contain hidden instructions.
- [DATA_EXFILTRATION]: The documentation promotes secure development practices by instructing users to store API keys in environment variables (e.g.,
A2A_API_KEY) and providing explicit warnings against hardcoding secrets in source code or prompts. - [EXTERNAL_DOWNLOADS]: The skill references the
@agent-native/corepackage, which serves as the core framework for the agents described in the documentation. - [PROMPT_INJECTION]: As an inter-agent communication protocol, the system naturally ingests data from external agents. While this represents a potential surface for indirect prompt injection, the skill itself is purely instructional and does not introduce vulnerabilities or malicious payloads.
Audit Metadata