a2a-messages-parts

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes message parts (TextPart, FilePart, DataPart) which may contain instructions or data from external agents, creating an attack surface for indirect prompt injection.
  • Ingestion points: Protocol documentation and schemas fetched from a2a-protocol.org and sample code from github.com/a2aproject (referenced in SKILL.md).
  • Boundary markers: There are no instructions to use delimiters or specific warnings to ignore embedded instructions within the processed message parts.
  • Capability inventory: The skill is configured with access to powerful tools including Bash, Write, Edit, and WebFetch across its execution environment.
  • Sanitization: The instructions do not define any validation, escaping, or content filtering mechanisms for the message parts being parsed.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch documentation and schemas from https://a2a-protocol.org/latest/specification/ and search for implementation examples within the a2aproject organization on GitHub.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:32 PM