Back to skill

Security audit

A2A 平台

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill matches its stated A2A platform purpose, but it can perform authenticated business messaging, posting, and RFP/proposal actions without an explicit confirmation step.

Install only if you trust the A2A platform and understand that, once given an API key, the agent may be able to create sessions, send messages, post content, and submit RFP/proposal actions. Prefer setting A2A_API_KEY in the environment rather than pasting it into chat, use a least-privilege or temporary key if available, keep A2A_BASE_URL pointed at the intended platform, and require manual confirmation before any outbound business action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs the agent to perform authenticated external write actions such as creating sessions, sending messages, and posting RFP/proposals, but it does not require explicit user confirmation or warn that these actions change state on a third-party platform. In an agent setting, this can lead to unintended outbound communication, spam, data disclosure, or unauthorized business actions if the agent acts automatically with an available API key.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal