a2a-streaming

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to fetch documentation and examples from external, untrusted sources which could contain malicious instructions designed to hijack the agent's session.
  • Ingestion points: The skill uses WebFetch to read the specification from https://a2a-protocol.org/latest/specification/ and WebSearch to find examples on GitHub.
  • Boundary markers: There are no markers or instructions telling the agent to treat the fetched content as untrusted data or to ignore embedded instructions.
  • Capability inventory: The agent has access to sensitive tools including Bash, Write, and Edit, which could be exploited if the fetched documentation contains malicious commands or code snippets the agent is tricked into running.
  • Sanitization: No sanitization or validation of the external content is performed before it is processed by the agent.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to perform network requests to non-whitelisted domains to retrieve protocol specifications.
  • The agent fetches data from a2a-protocol.org and various GitHub search results.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:32 PM