Back to skill

Security audit

A2A 智能体间通信协议

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed A2A communication guide, but users should treat its optional registry and Feishu integrations as data-sharing features.

Before installing, confirm you have the missing runtime files from the publisher, run any A2A server only on networks you trust, avoid publishing private IP/topology data to an untrusted registry, and enable Feishu notifications only for conversations that are acceptable to share with that third-party workspace.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The skill documents registering agent identity and network location with an external registry over plain HTTP, which transmits data to another service and may expose internal topology information. In this A2A context, sharing host/IP/port data can aid reconnaissance or allow interception/tampering if used on untrusted networks.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

bash
# 注册智能体
curl -X POST http://<注册表地址>:3099/register \
  -H "Content-Type: application/json" \
  -d '{"name":"若兰","host":"172.28.0.2","port":3100}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly documents forwarding conversation data to Feishu, but it does not include a clear privacy warning, data handling note, or consent requirement. In an agent-to-agent communication skill, this can cause operators to unknowingly transmit potentially sensitive prompts, replies, or metadata to a third-party service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The natural-language documentation and usage instructions are entirely in Chinese, and the file does not indicate that this is an optional locale or a region-specific requirement. Under SQP-3, forcing a specific language without user opt-in can constitute a language/locale policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.