a2a-jsonrpc-transport

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and process data from external sources, which constitutes a potential attack surface.
  • Ingestion points: The agent is directed in SKILL.md to fetch live documentation from https://a2a-protocol.org/latest/specification/ and https://www.jsonrpc.org/specification, as well as to process results from a web search targeting GitHub.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore potential instructions embedded within the external documentation.
  • Capability inventory: The skill is granted access to high-privilege tools such as Bash, Write, and Edit, which could be misused if the external data contains actionable malicious prompts.
  • Sanitization: The instructions lack any requirement for the agent to sanitize or validate the integrity of the content retrieved from the remote URLs before acting upon it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:32 PM