square-automation

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from the Square API and lacks explicit instructions to sanitize this content, creating a risk if that data contains malicious instructions for the agent.
  • Ingestion points: Tools like SQUARE_LIST_PAYMENTS, SQUARE_SEARCH_ORDERS, SQUARE_RETRIEVE_ORDER, SQUARE_GET_INVOICE, and SQUARE_LIST_INVOICES ingest external data into the agent's context.
  • Boundary markers: The instructions do not define delimiters or warnings to ignore instructions embedded in the Square resource data.
  • Capability inventory: The skill has modification capabilities, including SQUARE_CANCEL_PAYMENT, SQUARE_UPDATE_ORDER, and SQUARE_CANCEL_INVOICE.
  • Sanitization: There is no mention of sanitizing, escaping, or validating the content retrieved from Square before it is processed by the agent.
  • [EXTERNAL_DOWNLOADS]: The skill requires the user to connect to an external MCP server endpoint to provide its functionality.
  • Evidence: Instructions in SKILL.md direct the user to add https://rube.app/mcp as an MCP server.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 09:50 PM