agent-engine
Fail
Audited by Snyk on May 6, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.80). The prompt includes examples that embed secrets directly into deployment configs/env_vars (e.g., "env_vars": {"API_KEY": "...", "DATABASE_URL": "..."}) which would require an agent to place secret values verbatim into generated code/configs, creating an exfiltration risk.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill's documentation instructs using RemoteA2aAgent and service-discovery patterns that "fetch agent cards" from URLs (/.well-known/agent.json) and to supply agent URLs via env_vars (e.g., PTO_AGENT_URL, HR_AGENT_URL) — evidence in references/advanced_deployment.md — which means the agent will fetch and interpret external agent-card JSON from third-party/untrusted endpoints that can change tool capabilities and behavior.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.70). The skill constructs and uses runtime agent URLs such as "https://us-central1-aiplatform.googleapis.com/v1/{pto_remote.resource_name}" (passed via env vars like PTO_AGENT_URL) which RemoteA2aAgent will automatically fetch (including the /.well-known/agent.json agent card) at runtime to obtain capabilities/tools that directly influence agent behavior and execution, so this is a runtime external dependency controlling prompts/behaviour.
Issues (3)
W007
HIGHInsecure credential handling detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata