google-adk-agent
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines prompt templates and agent structures that ingest untrusted user input, creating a potential surface for indirect prompt injection.
- Ingestion points: The
COORDINATOR_PROMPTinresources/prompt_template.pyis designed to analyze and act upon the user's request. - Boundary markers: The prompt templates do not implement specific delimiters or instructions to ignore embedded commands within user-provided data.
- Capability inventory: The
LlmAgentdefinition inresources/agent_template.pyincludes atoolsparameter, which allows the agent to execute delegated tasks via specialized sub-agents or external tools. - Sanitization: There is no evidence of input validation or sanitization within the provided Python templates.
- [EXTERNAL_DOWNLOADS]: The skill references official Google GitHub repositories and documentation sites. These links provide legitimate resources for the Agent Development Kit (ADK) and academic research samples.
Audit Metadata