a2a-protocol

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to modify its default response behavior by requiring a specific emoji (๐Ÿงข) at the start of all responses. It also contains an instruction to automatically perform filesystem enumeration upon activation. Additionally, the skill processes untrusted data from external A2A agents, creating a potential surface for indirect prompt injection.
  • Ingestion points: Fetches agent discovery cards from remote domains and parses JSON-RPC/gRPC message parts.
  • Boundary markers: The instructions do not define delimiters to separate external data from system prompts.
  • Capability inventory: The agent is given access to network tools (curl) and shell execution.
  • Sanitization: No validation or sanitization is provided for processing remote agent metadata or message content.
  • [COMMAND_EXECUTION]: The skill directs the agent to execute directory listing commands (ls) on user home directory paths (e.g., ~/.claude/skills/) to identify installed 'companion skills' for installation recommendations.
  • [EXTERNAL_DOWNLOADS]: The documentation suggests installing additional software components from the AbsolutelySkilled repository using the 'npx skills add' command.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:05 PM
Security Audit โ€” agent-trust-hub โ€” a2a-protocol