Atlas / MCP servers / rubenszimbres / A2A ADK

A2A ADKBLOCK

mcp/rubenszimbres/a2a-adk

Multi-Agent Systems with Google's Agent Development Kit + A2A + MCP

Verdict
BLOCK
Grade
F
Trust score
60 /100
Exposed tools
4 2r · 2w · 0d
Transport
stdio
License
Apache-2.0
Stars
2
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A security-focused, multi-agent data processing pipeline that combines the Agent-to-Agent (A2A) protocol, Google Agent Development Kit (ADK), and the Model Context Protocol (MCP). The system enables secure natural-language querying of a salary database through a sequential pipeline of specialized agents that enforce threat detection, SQL execution, and PII masking.

Table of Contents

  • Architecture Overview
  • Agent Pipeline
  • Security Model
  • MCP Integration
  • A2A Protocol
  • Project Structure
  • Technology Stack
  • Setup & Installation
  • Usage
  • Evaluation & Testing
  • Deployment
  • Documentation

Architecture Overview

The system is composed of three independent layers that collaborate to process every request securely:

┌─────────────────────────────────────────────────────────────┐
│                        CLIENT LAYER                         │
│          query_MCP_ADK_A2A.py  ·  a2a_client.py            │
└────────────────────┬────────────────────────────────────────┘
│  JSON-RPC 2.0 over HTTP
┌────────────────────▼────────────────────────────────────────┐
│                     A2A PROTOCOL LAYER                       │
│   Judge Server :10002  ·  SQL Server :10004  ·  Mask :10003 │
│              a2a_servers.py  ·  task_manager.py              │
└────────────────────┬────────────────────────────────────────┘
│  ADK agent callbacks
┌────────────────────▼────────────────────────────────────────┐
│                      ADK AGENT LAYER                         │
│       Judge Agent  →  SQL Agent  →  Mask Agent               │
│                      agent.py                                │
└──────┬──────
Read from source at commit da81aa88f3c9OBSERVED · 2026-10-08
02

Exposed tools (4)

2 read · 2 write · 0 destructive.

ToolRiskDescription
execute_sql_querywriteValidate then run a read-only SELECT on the salaries database.
get_table_inforeadGet schema and sample data for specified tables (comma-separated).
list_database_tablesreadList all tables in the database.
query_datawriteRun a read-only SELECT against the salaries database.
03

Trust audit

BLOCKgrade F · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (13)

HIGHHard-coded secrets · inv.env_committed · CWE-798, CWE-321
agents/.env
.env
Why it matters. a real .env in the package
Fix. ship .env.example with placeholders only
HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
clients/query_MCP_ADK_A2A.py:424
r"sudo",        # Simplified
Why it matters. asks for elevated privileges
HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
clients/query_MCP_ADK_A2A.py:430
r"sudo\s+.*",            # Match any sudo command
Why it matters. asks for elevated privileges
HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
clients/query_MCP_ADK_A2A.py:465
r"(sudo|rm|wget|curl|nc)\s+.*-[rflsp]+.*",  # Match command with dangerous flags
Why it matters. asks for elevated privileges
HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
clients/query_MCP_ADK_A2A.py:466
r";\s*(sudo|rm|wget|curl|nc)\s+.*",         # Match commands after semicolon
Why it matters. asks for elevated privileges
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
run_instruction.md:8
query → judge agent   (Model Armor: prompt injection / jailbreak screening)
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
MEDIUMInventory / provenance · inv.binary · CWE-1104
salaries.db
salaries.db
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
agents/.env
.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/test_security_controls.py:133
exec(cls, namespace)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/test_sql_read_only.py:36
exec(block, namespace)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements-dev.txt
pytest, pytest-asyncio
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
fastapi, google-adk, loguru, python-dotenv, requests, aiohttp
Why it matters. 6 requirement(s) not pinned with ==
Fix. pin exact versions
INFOPrompt injection · scope.undeclared_system · CWE-94, CWE-1427
<declared scope>
system use found in code, not declared in the description
Why it matters. the description does not admit a capability the code has
Fix. declare system use in the description, or remove it

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha da81aa88f3c9full audit observations/trust-audit/mcp-server/rubenszimbres__a2a-adk.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08da81aa88f3c9BLOCKF60first audit
05

Questions

What is the A2A ADK MCP server?

Multi-Agent Systems with Google's Agent Development Kit + A2A + MCP

What tools does A2A ADK expose?

4 in total: 2 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is A2A ADK safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (60/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does A2A ADK need?

It reads GOOGLE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does A2A ADK run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (da81aa88f3c9), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement