a2a-error-handling
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill incorporates external data ingestion by fetching specifications and searching GitHub for implementation examples, creating a potential vector for instructions embedded in remote content to influence the agent.
- Ingestion points: The skill instructs the agent to use
WebFetchforhttps://a2a-protocol.org/latest/specification/andWebSearchfora2aprojecterror codes and samples on GitHub. - Boundary markers: There are no instructions providing delimiters or specific guidance to ignore potential commands within the fetched external data.
- Capability inventory: The skill utilizes
Bash,Write,Edit, andGreptools, which could be used to modify the environment or local files based on instructions found in the external documentation. - Sanitization: The instructions do not specify any validation, filtering, or sanitization steps for the data retrieved from external URLs or search results.
Audit Metadata