a2a-streaming
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to fetch documentation and examples from external, untrusted sources which could contain malicious instructions designed to hijack the agent's session.
- Ingestion points: The skill uses
WebFetchto read the specification fromhttps://a2a-protocol.org/latest/specification/andWebSearchto find examples on GitHub. - Boundary markers: There are no markers or instructions telling the agent to treat the fetched content as untrusted data or to ignore embedded instructions.
- Capability inventory: The agent has access to sensitive tools including
Bash,Write, andEdit, which could be exploited if the fetched documentation contains malicious commands or code snippets the agent is tricked into running. - Sanitization: No sanitization or validation of the external content is performed before it is processed by the agent.
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to perform network requests to non-whitelisted domains to retrieve protocol specifications.
- The agent fetches data from
a2a-protocol.organd various GitHub search results.
Audit Metadata