a2a-messages-parts
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes message parts (TextPart, FilePart, DataPart) which may contain instructions or data from external agents, creating an attack surface for indirect prompt injection.
- Ingestion points: Protocol documentation and schemas fetched from
a2a-protocol.organd sample code fromgithub.com/a2aproject(referenced inSKILL.md). - Boundary markers: There are no instructions to use delimiters or specific warnings to ignore embedded instructions within the processed message parts.
- Capability inventory: The skill is configured with access to powerful tools including
Bash,Write,Edit, andWebFetchacross its execution environment. - Sanitization: The instructions do not define any validation, escaping, or content filtering mechanisms for the message parts being parsed.
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch documentation and schemas from
https://a2a-protocol.org/latest/specification/and search for implementation examples within thea2aprojectorganization on GitHub.
Audit Metadata