Back to skill

Security audit

A2a Server

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent A2A WebSocket skill, but its current server allows unauthenticated agent impersonation and message relay, so users should review it carefully before use.

Install or run this only in a trusted local development environment. Do not expose the WebSocket port to shared or public networks, and do not route sensitive prompts, credentials, tool requests, or privileged agent actions through it until authentication, authorization, message signing, TLS/WSS, payload limits, queue quotas, and rate limits are implemented.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/server.js:223
Finding

Unauthenticated Agent Impersonation and Missing Connection-Level Authorization

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/server.js:548
Finding

Unauthenticated Resource Exhaustion Through Unbounded Offline Targets and Message Payloads

Content
View full analysis
{ if (!agentId) { this.log(`${clientId} registration timeout; disconnecting`); ws.close(4000, 'Registration timeout'); } }, 30000); ws.on('message', (data) => { try { const message = JSON.parse(data.toString()); this.handleMessage(ws, message, clientId); if (message.type === 'register' && !agentId) { clearTimeout(registrationTimeout); } } catch (error) { this.log('Message parsing error:', error.message); ws.send(JSON.stringify({ type: 'error', error: 'Invalid message format' })); } }); ``` Calls to nonexistent attacker-selected targets create offline queues: ```javascript const targetAgent = this.agents.get(to); if (!targetAgent) { this.queueMessage(to, message); ws.send(JSON.stringify({ type: 'error', correlationId, error: `Agent ${to} is offline`, queued: true })); return; } ``` The per-target message count is limited, but the target count and retained byte size are not: ```javascript queueMessage(agentId, message) { if (!this.messageQueue.has(agentId)) { this.messageQueue.set(agentId, []); } const queue = this.messageQueue.get(agentId); queue.push({ ...message, queuedAt: new Date() }); // Limit queue size if (queue.length > 100) { queue.shift(); } this.log(`Message queued: ${agentId} (${queue.length})`); } ...[truncated 3101 chars]
Remediation
View remediation
{ const agent = this.agents.get(agentId); if (agent && agent.ws === ws) { this.unregisterAgent(agentId); } }); ``` 10. Clear the registration timeout only after the server confirms successful authenticated registration, not merely when a message has `type: "register"`. 11. Introduce global connection limits, idle timeouts, backpressure handling, and monitoring for queue bytes, rejected messages, heap usage, and per-client request rates. 12. Add denial-of-service tests using numerous unique targets, oversized payloads, rapid connection churn, and failed registration messages. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (32)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
node src/server.js

Known Vulnerable Dependency: brace-expansion==1.1.12 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
91% confidence
Finding

brace-expansion 1.1.12 has multiple reported denial-of-service issues involving pathological expansion patterns that can trigger exponential work, hangs, or memory exhaustion. Because it is a common transitive dependency of globbing/matching stacks, its presence is a real vulnerability when any untrusted glob-like patterns can be introduced into test, build, or automation flows.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: browserslist==4.28.1 — 2 advisory(ies): CVE-2026-73088 (Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.); CVE-2026-73089 (Browserslist: Unbounded memory growth (no cache eviction) via distinct query res)

High
Category
Supply Chain
Confidence
85% confidence
Finding

browserslist 4.28.1 is flagged for crash/prototype-write and memory-growth issues when handling untrusted browserslist-stats or many distinct queries. This is a real vulnerability in the dependency tree, but in this repository it likely affects developer tooling and CI rather than the production WebSocket server unless external data is fed into browserslist-related tooling.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: js-yaml==3.14.2 — 4 advisory(ies): CVE-2026-84375 (js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources); CVE-2026-59869 (js-yaml: YAML merge-key chains can force quadratic CPU consumption); GHSA-5p4m-2wfm-xmqj (JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026) +1 more

High
Category
Supply Chain
Confidence
92% confidence
Finding

js-yaml 3.14.2 is present with several CPU-consumption advisories involving crafted YAML structures such as merge-key chains and omap resolution. This is a genuine parser-level denial-of-service risk whenever untrusted YAML may be parsed, and even as a dev dependency it can still affect CI, scripts, or developer machines if attacker-controlled config files are introduced.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: picomatch==2.3.1 — 2 advisory(ies): CVE-2026-33672 (Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Mat); CVE-2026-33671 (Picomatch has a ReDoS vulnerability via extglob quantifiers)

High
Category
Supply Chain
Confidence
89% confidence
Finding

picomatch 2.3.1 has reported ReDoS and method-injection issues in glob pattern handling, making it vulnerable to attacker-crafted matching expressions that consume excessive CPU or alter matching behavior. As a transitive dependency used widely in build and test tooling, this is a real risk if any external input can influence file matching patterns.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file contains all headings and operational notes in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the policy rule, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document provides copy-pasteable instructions to start a WebSocket server and perform remote agent discovery/calls, but it does not warn that this exposes a network service and enables inbound/outbound interaction with other agents. In the broader file context, trust-chain authorization is explicitly not yet implemented, which increases the likelihood that users deploy an unauthenticated or weakly protected remote control surface.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README promotes agent discovery, P2P forwarding, RPC, offline queues, and heartbeat-based communication without any warning that trust/authentication safeguards are absent. In this context, users may reasonably deploy the service as a coordination plane for privileged agents, which creates a high-risk trust boundary failure where unauthorized agents can discover peers and send or relay dangerous requests.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly states that trust-chain authorization and message signing are not yet implemented, while the rest of the document presents the A2A server/client as usable for agent registration, discovery, RPC, and pub/sub. In an agent-to-agent communication system, missing authentication and integrity controls means any reachable party may impersonate agents, tamper with messages, or invoke sensitive remote actions, especially given the documented remote execution-style integrations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The quick-start instructs users to install, start, and connect to a WebSocket server immediately, but does not warn about exposing it to other hosts or transmitting sensitive payloads. Because the examples encourage real agent traffic and RPC usage, this omission increases the likelihood of insecure deployment, interception, unauthorized connection, or misuse in environments where localhost defaults are later changed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documents a WebSocket-based agent communication system while explicitly noting later that authentication, authorization, and message signing are not implemented. Because the early description and quick-start sections emphasize P2P/RPC/pub-sub usage without an upfront security warning, users may deploy it for real agent coordination and transmit sensitive prompts, metadata, or tool requests over an unauthenticated channel, enabling spoofing, unauthorized participation, and message tampering.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JavaScript file contains user-facing comments and console output entirely in Chinese, including the title and all runtime status messages. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code file performs network transmission of agent identity, capabilities, metadata, and later arbitrary payloads over a WebSocket connection, but it provides no confirmation prompt or explicit user-facing disclosure beyond optional verbose debug logs. Because these messages may contain user or system data and network transmission is safety-relevant, the absence of a warning is a quality/safety issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code file creates a network-facing WebSocket server and subsequently transmits agent-provided payloads, metadata, and routing information across connections. Although the header describes the server's purpose, there is no explicit user-facing warning, confirmation, or disclosure in code comments/logging about sending potentially sensitive agent or system data over the network.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Nearly all user-facing documentation in this file is written in Chinese, with no indication that other languages are available or that the locale is intentionally limited. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The natural-language documentation and usage guidance are presented in Chinese, but the file does not indicate that the language is optional or provide an alternative locale. Per the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all user-facing documentation in a single language, which can violate language/locale policy when no user opt-in or justification is provided. There is no indication that the skill is region-specific or that alternate language support is intentionally constrained.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This file contains many natural-language strings and comments in Chinese, including runtime log messages such as connection, registration, and error notifications. Because the skill does not offer language selection or justify a Chinese-only locale, it may violate the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The document sets lang="en", which is a natural-language locale choice embedded in the file. In the provided content, there is no indication that this language setting is user-selectable or specifically justified as a region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language descriptions and user-facing console output in Chinese, which imposes a specific language on users of the example. The policy allows locale constraints only when users are given a choice or the constraint is clearly documented and justified, neither of which appears here.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @babel/core==7.29.0 — 1 advisory(ies): CVE-2026-49356 (@babel/core: Arbitrary File Read via sourceMappingURL Comment)

Low
Category
Supply Chain
Confidence
77% confidence
Finding

The lockfile pins @babel/core 7.29.0, and the cited advisory describes an arbitrary file read condition tied to parsing or honoring crafted sourceMappingURL comments. In this package-lock context it is a real supply-chain risk because vulnerable code is present in the dependency tree, though it is dev-only and there is no evidence in this file alone that untrusted attacker-controlled input reaches Babel at runtime.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: baseline-browser-mapping==2.10.9 — 1 advisory(ies): CVE-2026-45819 (baseline-browser-mapping process termination on invalid input causes denial of s)

Low
Category
Supply Chain
Confidence
74% confidence
Finding

baseline-browser-mapping 2.10.9 is present and the advisory indicates malformed input can terminate the process, which is a genuine denial-of-service concern in tooling that consumes untrusted data. Here it appears as a transitive dev dependency, so the practical exposure is limited to build/test workflows rather than the ws/uuid production runtime shown at the top of the lockfile.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 23)May include surrounding context.

json
"author": "小蒲萄 (Clawd)",
  "license": "MIT",
  "dependencies": {
    "uuid": "^9.0.0",
    "ws": "^8.16.0"
  },
  "devDependencies": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 24)May include surrounding context.

json
"license": "MIT",
  "dependencies": {
    "uuid": "^9.0.0",
    "ws": "^8.16.0"
  },
  "devDependencies": {
    "jest": "^29.7.0",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 27)May include surrounding context.

json
"ws": "^8.16.0"
  },
  "devDependencies": {
    "jest": "^29.7.0",
    "jest-websocket-mock": "^2.5.0"
  },
  "engines": {

Static analysis

No suspicious patterns detected.