a2a-protocol

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands (ls) to scan specific local directories (e.g., ~/.claude/skills/) for the presence of companion skills. While used for a 'Companion check' feature to recommend related skills, this behavior constitutes local environment enumeration.
  • [PROMPT_INJECTION]: The skill is designed to interact with external A2A agents, creating a surface for indirect prompt injection. * Ingestion points: Untrusted data enters the agent context when it fetches remote agent-card.json files or processes incoming A2A messages via JSON-RPC, gRPC, or REST bindings. * Boundary markers: The instructions lack delimiters or explicit warnings to ignore instructions embedded within the external protocol data. * Capability inventory: The agent has capabilities to execute shell commands (e.g., ls for environment checks, curl for agent discovery) and interact with the filesystem. * Sanitization: No validation or sanitization mechanisms are defined for processing the content of external messages or agent metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 03:03 PM
Security Audit — agent-trust-hub — a2a-protocol