a2a-mcp-bridge

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and process external protocol specifications and search results, creating a surface where instructions embedded in that external data could influence agent behavior.
  • Ingestion points: The agent is instructed to use WebFetch on https://a2a-protocol.org/latest/specification/ and perform several WebSearch queries to gather integration patterns.
  • Boundary markers: There are no explicit instructions or delimiters defined to separate the fetched content from the agent's internal instructions.
  • Capability inventory: The skill has access to powerful tools including Bash, Write, and Edit which could be misused if the agent obeys instructions found in external documents.
  • Sanitization: No sanitization or validation logic is provided for the external documentation before it is processed.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves documentation from https://a2a-protocol.org/latest/specification/. This is the official project site for the A2A protocol and fetching its specification is a routine task for the skill's stated purpose of building protocol bridges.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM