a2a
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a legitimate multi-tier architecture using the Google ADK and Vertex AI Agent Engine. All code examples utilize official SDKs and standard Python practices.
- [EXTERNAL_DOWNLOADS]: The skill fetches agent configuration data (AgentCards) from URLs to facilitate service discovery, which is the intended functionality of the A2A protocol. These requests are performed using standard libraries like
requestsandhttpxto access specified endpoints. - [SAFE]: The multi-agent communication flow presents a surface for indirect prompt injection, where user input is passed between different agents. The skill documentation explicitly addresses this risk in the provided protocol reference, advising on security best practices such as input validation and authorization.
- Ingestion points: User queries are ingested by the orchestrator and delegated to downstream functional and leaf agents.
- Boundary markers: No explicit delimiter markers are used in the basic prompt templates provided in the examples.
- Capability inventory: Agents possess capabilities to call tools, interact with other agents via network requests, and search document stores using Discovery Engine.
- Sanitization: The included protocol guide recommends implementing validation and security controls at each agent level.
Audit Metadata