a2a-dev-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill performs network requests to an external, non-whitelisted domain to fetch protocol documentation. * Evidence: Instruction to fetch 'https://a2a-protocol.org/latest/specification/' using the WebFetch tool in 'SKILL.md'.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes content from external documentation and web search results, creating a potential surface for instruction injection. * Ingestion points: External documentation fetched from 'a2a-protocol.org' and various search results retrieved via the WebSearch tool as instructed in 'SKILL.md'. * Boundary markers: Absent. The skill does not provide instructions to the agent to treat fetched content as untrusted or to use delimiters to separate external data from system instructions. * Capability inventory: The skill environment includes 'Bash', 'Write', 'Edit', and 'Grep' tools, which could be targeted for abuse if the agent follows malicious instructions embedded in external content. * Sanitization: Absent. The instructions do not include steps for the agent to validate, filter, or sanitize the content retrieved from external sources before acting upon it.
Audit Metadata