acme-shop
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes data from an external catalog. Ingestion points: Product names and descriptions returned from the 'GET /v1/products/search' endpoint in SKILL.md. Boundary markers: None identified in the prompt templates. Capability inventory: The skill can trigger network requests and payment flows via the 'POST /v1/orders' endpoint in SKILL.md. Sanitization: No sanitization or validation of the ingested product data is mentioned.
- [DATA_EXFILTRATION]: The skill collects and transmits sensitive user information, including full name and complete shipping address, to the base_url 'https://api.acme.shop' and the payment facilitator 'https://facilitator.402.md'. While required for order fulfillment, this involves the transfer of PII to third-party services.
- [EXTERNAL_DOWNLOADS]: The documentation references external Node.js packages '@402md/x402' and '@402md/mcp' for transaction signing and payment handling. These are vendor-provided resources associated with the skill author.
Audit Metadata