a2ui
Pass
Audited by Gen Agent Trust Hub on Apr 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to perform an environment scan to identify installed companion tools.
- Evidence: Executing
lson multiple skill directories (e.g.,~/.claude/skills/) withinSKILL.mdto detect missing recommended components. - Purpose: This check is used to offer context-aware installation commands for relevant complementary skills.
- [EXTERNAL_DOWNLOADS]: Provides instructions for obtaining required SDKs and repositories from trusted public registries.
- Evidence: Installation procedures for
google-adk,@a2ui/web-lib, andflutter_genuivia standard package managers. - Evidence: Clones the official project repository from
https://github.com/google/a2ui.gitfor demonstration purposes. - [SAFE]: Demonstrates a focus on security by including explicit instructions for maintaining data privacy in multi-agent systems.
- Evidence: Documentation in
references/catalogs-and-actions.mdadvises stripping internal metadata before sharing data models to prevent cross-agent data leakage.
Audit Metadata