a2a-mcp-bridge
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and process external protocol specifications and search results, creating a surface where instructions embedded in that external data could influence agent behavior.
- Ingestion points: The agent is instructed to use
WebFetchonhttps://a2a-protocol.org/latest/specification/and perform severalWebSearchqueries to gather integration patterns. - Boundary markers: There are no explicit instructions or delimiters defined to separate the fetched content from the agent's internal instructions.
- Capability inventory: The skill has access to powerful tools including
Bash,Write, andEditwhich could be misused if the agent obeys instructions found in external documents. - Sanitization: No sanitization or validation logic is provided for the external documentation before it is processed.
- [EXTERNAL_DOWNLOADS]: The skill retrieves documentation from
https://a2a-protocol.org/latest/specification/. This is the official project site for the A2A protocol and fetching its specification is a routine task for the skill's stated purpose of building protocol bridges.
Audit Metadata