agent-to-agent
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's architecture is built around multiple Claude agents reading from and writing to a shared context file,
.a2a-context.json. This design creates a surface for indirect prompt injection where one agent (such as a 'Researcher' processing untrusted web content) could inadvertently introduce malicious instructions into the shared context that are subsequently processed by the 'Coordinator' or other agents. - Ingestion points: All participating agents, including the Coordinator, ingest data from the
.a2a-context.jsonfile located in the project root (SKILL.md, references/protocol.md). - Boundary markers: The protocol utilizes a structured JSON schema and defines specific sections for each agent to limit data overwriting (references/protocol.md). However, it does not mandate specific delimiters or "ignore embedded instructions" warnings for the content within those sections.
- Capability inventory: The skill environment includes powerful tools such as
Agent(for spawning new instances),Bash(for shell execution),Write, andRead(SKILL.md, references/registry.md). - Sanitization: While the documentation emphasizes security best practices like excluding secrets from the context file and using
.gitignore, it does not specify methods for sanitizing or validating the actual natural language content generated by sub-agents before it is used by other agents in the pipeline (references/operations.md).
Audit Metadata