A2A ADKBLOCK
Multi-Agent Systems with Google's Agent Development Kit + A2A + MCP
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A security-focused, multi-agent data processing pipeline that combines the Agent-to-Agent (A2A) protocol, Google Agent Development Kit (ADK), and the Model Context Protocol (MCP). The system enables secure natural-language querying of a salary database through a sequential pipeline of specialized agents that enforce threat detection, SQL execution, and PII masking.
Table of Contents
- Architecture Overview
- Agent Pipeline
- Security Model
- MCP Integration
- A2A Protocol
- Project Structure
- Technology Stack
- Setup & Installation
- Usage
- Evaluation & Testing
- Deployment
- Documentation
Architecture Overview
The system is composed of three independent layers that collaborate to process every request securely:
┌─────────────────────────────────────────────────────────────┐ │ CLIENT LAYER │ │ query_MCP_ADK_A2A.py · a2a_client.py │ └────────────────────┬────────────────────────────────────────┘ │ JSON-RPC 2.0 over HTTP ┌────────────────────▼────────────────────────────────────────┐ │ A2A PROTOCOL LAYER │ │ Judge Server :10002 · SQL Server :10004 · Mask :10003 │ │ a2a_servers.py · task_manager.py │ └────────────────────┬────────────────────────────────────────┘ │ ADK agent callbacks ┌────────────────────▼────────────────────────────────────────┐ │ ADK AGENT LAYER │ │ Judge Agent → SQL Agent → Mask Agent │ │ agent.py │ └──────┬──────
da81aa88f3c9OBSERVED · 2026-10-08Exposed tools (4)
2 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
execute_sql_query | write | Validate then run a read-only SELECT on the salaries database. |
get_table_info | read | Get schema and sample data for specified tables (comma-separated). |
list_database_tables | read | List all tables in the database. |
query_data | write | Run a read-only SELECT against the salaries database. |
Trust audit
BLOCKgrade F · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (13)
.env
r"sudo", # Simplified
r"sudo\s+.*", # Match any sudo command
r"(sudo|rm|wget|curl|nc)\s+.*-[rflsp]+.*", # Match command with dangerous flags
r";\s*(sudo|rm|wget|curl|nc)\s+.*", # Match commands after semicolon
query → judge agent (Model Armor: prompt injection / jailbreak screening)
salaries.db
.env
exec(cls, namespace)
exec(block, namespace)
pytest, pytest-asyncio
fastapi, google-adk, loguru, python-dotenv, requests, aiohttp
system use found in code, not declared in the description
Gates applied: instruction_override, no_behavioural_pass.
da81aa88f3c9full audit observations/trust-audit/mcp-server/rubenszimbres__a2a-adk.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | da81aa88f3c9 | BLOCK | F | 60 | first audit |
Questions
What is the A2A ADK MCP server?
Multi-Agent Systems with Google's Agent Development Kit + A2A + MCP
What tools does A2A ADK expose?
4 in total: 2 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is A2A ADK safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (60/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does A2A ADK need?
It reads GOOGLE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does A2A ADK run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (da81aa88f3c9), read on 2026-10-08. The repository is watched and re-audited when it changes.