a2a-client
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for the agent to fetch and process external data, such as agent cards and task responses, which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: Fetching
{base_url}/.well-known/agent-card.jsonand processing responses from external agents viamessage/sendormessage/streamendpoints (SKILL.md). - Boundary markers: The instructions do not specify the use of delimiters or explicit instructions to ignore embedded commands when handling data from external agents.
- Capability inventory: The skill environment includes
Bash,Write,Edit, andWebFetchcapabilities (SKILL.md). - Sanitization: The instructions do not include steps for sanitizing or validating content received from external agents before processing it.
- [EXTERNAL_DOWNLOADS]: The skill references and fetches documentation and technical specifications from external domains to guide implementation.
- Evidence: Fetches protocol requirements from
https://a2a-protocol.org/latest/specification/(SKILL.md).
Audit Metadata