skills/google/sam/sam-a2a-bridge/Gen Agent Trust Hub

sam-a2a-bridge

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • Data Residency and Egress Control: The skill incorporates a security feature called 'required_labels'. This is designed to ensure that data only leaves the local node if the remote provider's environment matches specific jurisdiction or region requirements (e.g., region=eu-west-1), providing a mechanism to prevent accidental data exfiltration to unauthorized regions.
  • Indirect Prompt Injection Surface: As a bridge for multi-agent communication, the skill processes information, structured data, and files returned from remote peers via get_agent_task. While this is fundamental to the skill's purpose, it represents a potential surface where content from a remote agent could influence the local agent's operating context.
  • Manual Setup Instructions: The documentation includes shell commands for building the bridge and registering it with the MCP harness. These instructions are presented as manual steps intended for the user to verify and approve before execution, ensuring transparency during the configuration of the bridge server.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 05:37 PM
Security Audit — agent-trust-hub — sam-a2a-bridge