a2a-agent-card
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches specification documents from a2a-protocol.org and retrieves implementation samples via web searches. These actions are aligned with the skill's purpose of following official standards and using public examples.
- [PROMPT_INJECTION]: The skill instructs the agent to ingest and process data from external websites and search results. This presents an indirect prompt injection surface where a malicious website could attempt to influence the agent's behavior, although no such instructions are present in the skill itself. Evidence: 1. Ingestion points: WebFetch and WebSearch in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: Bash, Write, and Edit tools are available. 4. Sanitization: Absent.
Audit Metadata