Back to skill

Security audit

A2a Client

Security checks for vulnerabilities and agentic risk

Overview

This skill largely does what it claims, but it uses administrator-level gateway tokens for normal task actions and has unsafe input handling, so it needs review before use.

Install only in a trusted test environment or after changing the scripts to use scoped credentials instead of admin bootstrap, require HTTPS for non-local gateways, validate agent slugs, and avoid sending secrets or confidential work through external agents/providers.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
a2a-send-task.sh:112
Finding

Arbitrary Python Code Execution Through Agent Parameters

Content
View full analysis
/dev/null ``` The interpolated values originate from command-line arguments: ```bash --agent) AGENT="$2"; shift 2 ;; -- ...[truncated 2204 chars]
Remediation
View remediation
&2 exit 1 fi ``` - Apply equivalent validation to `TARGET_AGENT`. - Add regression tests containing quotes, newlines, semicolons, backslashes, and Python syntax in both parameters. - Avoid suppressing all Python errors with `2>/dev/null`, because suppression can conceal attempted exploitation and operational failures. ]]>

T05 · Unauthorized Access and Privilege Escalation

Error
Location
a2a-discover.sh:44
Finding

Routine Client Operations Acquire an Unnecessary Administrative JWT

Content
View full analysis
/dev/null | python3 -c " import sys, json try: data = json.load(sys.stdin) print(data.get('accessToken', '')) except: print('') " 2>/dev/null) if [[ -z "$AUTH_TOKEN" ]]; then echo "Error: Failed to obtain admin JWT from gateway" >&2 exit 1 fi # --- Try the A2A agents endpoint --- AGENTS_RESPONSE=$(curl -sS -w "\n%{http_code}" \ -X GET \ -H "Authorization: Bearer ${AUTH_TOKEN}" \ -H "Content-Type: application/json" \ "${GATEWAY_URL}/v1/a2a/agents" 2>/dev/null) ``` ```bash PROVIDERS_RESPONSE=$(curl -sS \ -H "Authorization: Bearer ${AUTH_TOKEN}" \ -H "Content-Type: application/json" \ "${GATEWAY_URL}/v0/admin/providers" 2>/dev/null) ``` `a2a-get-task.sh` repeats the administrative bootstrap flow for task retrieval: ```bash # --- Get admin JWT for API authentication --- AUTH_TOKEN=$(curl -sS "${GATEWAY_URL}/v0/admin/bootstrap" 2>/dev/null | python3 -c " import sys, json try: data = json.load(sys.stdin) print(data.get('accessToken', '')) except: print('') " 2>/dev/null) if [[ -z "$AUTH_TOKEN" ]]; then echo "Error: Failed to obtain admin JWT from gateway" >&2 exit 1 fi # --- Call the task status endpoint --- RESPONSE=$(curl -sS -w "\n%{http_code}" \ -X GET \ -H "Authorization: Bearer ${AUTH_TOKEN}" \ -H "Content-Type: application/json" \ "${GATEWAY_URL}/v1/a2a/tasks/${TASK_ID}") ``` `a2a-send-task.sh` also obtains and uses an administrative token: ```bash # --- Get admin JWT for API authentication --- AUTH_TOKEN= ...[truncated 3455 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:23
Finding

Administrative Credentials and Task Content Can Be Sent Over Plaintext HTTP

Content
View full analysis
/dev/null | python3 -c " import sys, json try: data = json.load(sys.stdin) print(data.get('accessToken', '')) except: print('') " 2>/dev/null) ``` The same URL is then used to transmit the bearer token and, for task submission, the full message payload: ```bash RESPONSE=$(curl -sS -w "\n%{http_code}" \ -X POST \ -H "Authorization: Bearer ${AUTH_TOKEN}" \ -H "Content-Type: application/json" \ -d "$PAYLOAD" \ "${GATEWAY_URL}/v1/a2a/tasks/send") ``` Task retrieval also sends the bearer token and receives task results over the configured transport: ```bash RESPONSE=$(curl -sS -w "\n%{http_code}" \ -X GET \ -H "Authorization: Bearer ${AUTH_TOKEN}" \ -H "Content-Type: application/json" \ "${GATEWAY_URL}/v1/a2a/tasks/${TASK_ID}") ``` ### Technical Analysis HTTP does not provide confidentiality, server authentication, or integrity. When `GATEWAY_URL` uses `http://`, the administrative bearer token, delegated task messages, task metadata, and returned results travel in plaintext. Because bearer tokens grant access to whoever possesses them, passive interception may be sufficient for credential theft. An active network attacker can also modify bootstrap or API responses, redirect task behavior at the application-data level, or capture sensitive prompt ...[truncated 1914 chars]
Remediation
View remediation
&2 ;; *) echo "Error: HTTPS is required for remote gateways" >&2 exit 1 ;; esac ``` - Update all documentation and examples to use HTTPS. - Keep curl’s default certificate verification enabled; do not introduce `-k` or `--insecure`. - For private deployments, install a trusted internal certificate authority rather than disabling validation. - Consider certificate pinning or mutual TLS where the gateway handles particularly sensitive tasks. - Replace the administrative JWT with a scoped client credential to reduce the impact of interception. - Use short token lifetimes, audience restrictions, narrow scopes, rotation, and server-side revocation. - Avoid placing secrets directly in command-line arguments because process listings and shell history can expose them; prefer protected configuration files, standard input, or a secret manager. - Restrict configuration-file permissions to the invoking account. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

This second mismatch likewise indicates the skill description understates a privileged authentication mechanism and overstates implemented user-facing functions. Security reviewers may approve or expose the skill based on an inaccurate trust model, while the actual design relies on admin-level bootstrap access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

This second mismatch likewise indicates the skill description understates a privileged authentication mechanism and overstates implemented user-facing functions. Security reviewers may approve or expose the skill based on an inaccurate trust model, while the actual design relies on admin-level bootstrap access.

Content

No source excerpt is available for this finding.

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

The skill supports selecting external providers/models for task execution, which creates a direct path for sensitive task content to be routed to third-party services. In this context, external model routing is materially dangerous because the skill is specifically designed to delegate arbitrary user work, and the documentation does not pair that power with strong trust-boundary or data-classification safeguards.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
./a2a-send-task.sh --agent groq --message "Analyze the Q3 sales data"

# Specific model
./a2a-send-task.sh --agent mistral --message "Draft a blog post" --model mistral/mistral-small-latest

# Route to a specific A2A agent
./a2a-send-task.sh --agent ozore --message "Refactor the auth module" --target-agent coder

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script performs agent discovery by calling the gateway's admin bootstrap endpoint and extracting an admin JWT, which grants elevated privileges unrelated to simple discovery. In this skill context, the code is specifically meant for routing and discovery, so silently escalating to administrator access is an unjustified privilege increase that expands blast radius if the script is run against a reachable gateway.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · a2a-discover.sh (reported line 45)May include surrounding context.

sh
fi

# --- Get admin JWT for API authentication ---
AUTH_TOKEN=$(curl -sS "${GATEWAY_URL}/v0/admin/bootstrap" 2>/dev/null | python3 -c "
import sys, json
try:
    data = json.load(sys.stdin)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · a2a-get-task.sh (reported line 48)May include surrounding context.

sh
fi

# --- Get admin JWT for API authentication ---
AUTH_TOKEN=$(curl -sS "${GATEWAY_URL}/v0/admin/bootstrap" 2>/dev/null | python3 -c "
import sys, json
try:
    data = json.load(sys.stdin)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script queries /v0/admin/providers using an admin bearer token, exposing administrative provider configuration that is not necessary to list available agents. This can leak internal provider inventory and model configuration details, and because this skill is designed for delegation/routing, embedding admin enumeration makes misuse more dangerous than a normal operational script.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · a2a-discover.sh (reported line 114)May include surrounding context.

sh
echo "Available LLM Providers:"
echo "───────────────────────────────────────────────────"

PROVIDERS_RESPONSE=$(curl -sS \
  -H "Authorization: Bearer ${AUTH_TOKEN}" \
  -H "Content-Type: application/json" \
  "${GATEWAY_URL}/v0/admin/providers" 2>/dev/null)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script obtains an admin JWT from the gateway bootstrap endpoint and then uses that privileged token to read task data, instead of using the provided API key or a least-privilege task-scoped credential. In an agent-routing skill, this is dangerous because it silently escalates privileges and may allow access to arbitrary tasks or broader administrative APIs if the bootstrap endpoint is exposed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script ignores the configured API key for authentication and instead requests an admin bootstrap token from the gateway. For a client whose stated purpose is only to send tasks, obtaining administrative credentials violates least privilege and can expose a broadly privileged token to any user of the skill or to unintended destinations if the gateway URL is misconfigured.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Using an administrative bootstrap capability in a task-sending client is unjustified by the skill's documented function and materially expands the blast radius of compromise. If an attacker can influence GATEWAY_URL or observe/intercept responses, they may obtain or misuse an admin JWT instead of a narrowly scoped client token.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

The script fetches data from an external endpoint and immediately treats the response as a credential source, extracting an access token from the bootstrap response. Although it does not execute fetched code, it still trusts remotely supplied authentication material from an admin endpoint, which is dangerous if the gateway URL is attacker-controlled, downgraded, or misconfigured.

Content

Scanner excerpt · a2a-send-task.sh (reported line 67)May include surrounding context.

sh
fi

# --- Get admin JWT for API authentication ---
AUTH_TOKEN=$(curl -sS "${GATEWAY_URL}/v0/admin/bootstrap" 2>/dev/null | python3 -c "
import sys, json
try:
    data = json.load(sys.stdin)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents shell-capable scripts but declares no explicit tool scope or permission boundary. In an agent ecosystem, undocumented shell capability increases the chance that the skill can be invoked with broader execution privileges than intended, making review and policy enforcement weaker.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages sending task messages and retrieving results through an external gateway and potentially onward to other agents/providers, but it does not prominently warn about data leaving the local trust boundary. Users may inadvertently send sensitive prompts, secrets, internal code, or results to third parties.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script advertises API-key-based configuration but then ignores the configured API key and instead authenticates through admin bootstrap. This mismatch can mislead operators into believing they are using scoped credentials when the script actually acquires far broader access, undermining security assumptions and auditability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script automatically retrieves an admin JWT from the bootstrap endpoint without disclosing that it is performing an administrative login or asking for confirmation. In a client skill intended for routine discovery, this hidden elevation increases the chance that users unintentionally perform privileged actions against a gateway they only meant to query.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script accepts and documents an API key but never uses it, instead later switching to admin bootstrap authentication. This mismatch is security-relevant because operators may believe they are using constrained credentials while the script actually performs a privileged authentication path, undermining review, auditing, and access control expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script makes a hidden network call to retrieve an admin JWT and uses it for subsequent privileged API access without any user-facing disclosure. In a delegation skill that contacts external agent infrastructure, undisclosed privileged remote authentication increases the chance of accidental misuse, over-privileged operation, and unsafe deployment in environments where users expect simple task-status checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The script silently performs a sensitive authentication bootstrap call to obtain an admin JWT without any user-facing warning. In this context, the lack of disclosure matters because the operation is not merely routine data transmission; it elevates privileges and may surprise users who expect the configured API key to be used.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · a2a-send-task.sh (reported line 95)May include surrounding context.

sh
" "$MODEL" "$AGENT" "$TARGET_AGENT" "$SESSION_ID" "$MESSAGE")

# --- Send the task ---
RESPONSE=$(curl -sS -w "\n%{http_code}" \
  -X POST \
  -H "Authorization: Bearer ${AUTH_TOKEN}" \
  -H "Content-Type: application/json" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code sends the user-supplied message, session ID, agent metadata, and bearer token to a remote gateway via HTTP, but there is no user-facing notice immediately before transmission describing what data is being sent. Although the script has comments, they are developer-facing and do not provide runtime disclosure to the user.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

L040 states that scripts automatically obtain an admin JWT from the gateway and that no manual auth handling is needed. However, the same file documents A2A_GATEWAY_API_KEY as required configuration/input for authentication in L025, L067-L078, and L119, so the documentation overstates the degree of automatic auth handling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.