adk

Warn

Audited by Snyk on May 6, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill's documentation and examples (SKILL.md and references/advanced_patterns.md) show agents fetching and consuming external content—e.g., RemoteA2aAgent configured with agent_card URLs (agent_card="http://.../.well-known/agent.json") and use of DiscoveryEngineSearchTool / google_search and external API callers—so the agent reads untrusted third-party web/search/agent-card content that can influence routing, tool use, and decisions.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill creates RemoteA2aAgent instances that fetch agent-card JSON at runtime (e.g., http://localhost:8001/.well-known/agent.json and similar HR/FINANCE agent_card URLs), which are runtime-fetched external resources that can directly control agent behavior/instructions and are required for the multi-agent workflow.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 6, 2026, 02:08 PM
Issues
2
Security Audit — snyk — adk