square-automation
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from the Square API and lacks explicit instructions to sanitize this content, creating a risk if that data contains malicious instructions for the agent.
- Ingestion points: Tools like
SQUARE_LIST_PAYMENTS,SQUARE_SEARCH_ORDERS,SQUARE_RETRIEVE_ORDER,SQUARE_GET_INVOICE, andSQUARE_LIST_INVOICESingest external data into the agent's context. - Boundary markers: The instructions do not define delimiters or warnings to ignore instructions embedded in the Square resource data.
- Capability inventory: The skill has modification capabilities, including
SQUARE_CANCEL_PAYMENT,SQUARE_UPDATE_ORDER, andSQUARE_CANCEL_INVOICE. - Sanitization: There is no mention of sanitizing, escaping, or validating the content retrieved from Square before it is processed by the agent.
- [EXTERNAL_DOWNLOADS]: The skill requires the user to connect to an external MCP server endpoint to provide its functionality.
- Evidence: Instructions in
SKILL.mddirect the user to addhttps://rube.app/mcpas an MCP server.
Audit Metadata