a2a-dev-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill performs network requests to an external, non-whitelisted domain to fetch protocol documentation. * Evidence: Instruction to fetch 'https://a2a-protocol.org/latest/specification/' using the WebFetch tool in 'SKILL.md'.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes content from external documentation and web search results, creating a potential surface for instruction injection. * Ingestion points: External documentation fetched from 'a2a-protocol.org' and various search results retrieved via the WebSearch tool as instructed in 'SKILL.md'. * Boundary markers: Absent. The skill does not provide instructions to the agent to treat fetched content as untrusted or to use delimiters to separate external data from system instructions. * Capability inventory: The skill environment includes 'Bash', 'Write', 'Edit', and 'Grep' tools, which could be targeted for abuse if the agent follows malicious instructions embedded in external content. * Sanitization: Absent. The instructions do not include steps for the agent to validate, filter, or sanitize the content retrieved from external sources before acting upon it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:32 PM