a2a-protocol

Pass

Audited by Gen Agent Trust Hub on Jul 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a technical guide for inter-agent communication and discovery. It does not perform any automated actions or contain hidden instructions.
  • [DATA_EXFILTRATION]: The documentation promotes secure development practices by instructing users to store API keys in environment variables (e.g., A2A_API_KEY) and providing explicit warnings against hardcoding secrets in source code or prompts.
  • [EXTERNAL_DOWNLOADS]: The skill references the @agent-native/core package, which serves as the core framework for the agents described in the documentation.
  • [PROMPT_INJECTION]: As an inter-agent communication protocol, the system naturally ingests data from external agents. While this represents a potential surface for indirect prompt injection, the skill itself is purely instructional and does not introduce vulnerabilities or malicious payloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 19, 2026, 04:41 AM
Security Audit — agent-trust-hub — a2a-protocol