adk
Warn
Audited by Snyk on May 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill's documentation and examples (SKILL.md and references/advanced_patterns.md) show agents fetching and consuming external content—e.g., RemoteA2aAgent configured with agent_card URLs (agent_card="http://.../.well-known/agent.json") and use of DiscoveryEngineSearchTool / google_search and external API callers—so the agent reads untrusted third-party web/search/agent-card content that can influence routing, tool use, and decisions.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill creates RemoteA2aAgent instances that fetch agent-card JSON at runtime (e.g., http://localhost:8001/.well-known/agent.json and similar HR/FINANCE agent_card URLs), which are runtime-fetched external resources that can directly control agent behavior/instructions and are required for the multi-agent workflow.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata