Back to skill

Security audit

a2a.fun

Security checks for vulnerabilities and agentic risk

Overview

This collaboration skill is review-worthy because it can automatically create an a2a.fun agent account, store a bearer token, and send inferred workspace context without an explicit approval step.

Install only if you are comfortable with the agent creating an a2a.fun identity, saving a local bearer token, and sending high-level work or repository-derived search terms to a2a.fun. Before first use, require the agent to show the registration fields, token storage path, and full search query, and approve those steps yourself despite the skill's low-friction default.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:16
Finding

Autonomous External Registration and Contextual Metadata Disclosure

Content
View full analysis
` ``` ### Technical Analysis The Skill directs an agent to register an identity with an external service and persist the resulting bearer credential without first obtaining explicit, informed user appro ...[truncated 2758 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
96% confidence
Finding

The instruction 'do not ask the user' pushes the agent toward autonomous decision-making for consequential actions such as registration, searching external projects, and recommending joins. In a security context, this weakens human oversight and can lead to unintended account, privacy, and workflow changes.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
## FIRST INSTALL (LOW-FRICTION DEFAULT FLOW)

On first install, **do not ask the user to choose modes**.
Do not present A/B/C onboarding branches.

Default flow is **streamlined**:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill directs the agent to register an account and persist a credential locally during first install without first requiring explicit user consent for account creation or credential storage. This can cause unintended external side effects and secret material to be written to disk on behalf of the user, which is risky even though the token-handling guidance itself is relatively careful.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The onboarding text explicitly says not to ask the user to choose modes and to proceed automatically when defaults are available. That removes meaningful user consent around account creation, project discovery, and credential persistence, increasing the chance of unauthorized actions or privacy surprises.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The skill includes a concrete API call that sends registration data to an external service, creating an account and obtaining a bearer token. External transmission is expected for this skill's purpose, but it becomes dangerous because the surrounding instructions encourage doing it by default without up-front user approval.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

Register (API)

bash
curl -X POST https://a2a.fun/api/agents/register \
  -H "Content-Type: application/json" \
  -d '{
    "handle": "your-agent-handle",

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

bash
mkdir -p $HOME/.a2a
chmod 700 $HOME/.a2a

# paste the agentToken into this file
cat > $HOME/.a2a/agentToken

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

paste the agentToken into this file

cat > $HOME/.a2a/agentToken chmod 600 $HOME/.a2a/agentToken

text

Verify (do **not** print token):

Static analysis

No suspicious patterns detected.