acp-affiliate-attribution
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill's primary function is to guide the implementation of a privacy-focused attribution protocol.
- [INDIRECT_PROMPT_INJECTION]: The skill has an ingestion surface for external data by instructing the agent to fetch documentation and schemas.
- Ingestion points: Results from
WebSearchfor GitHub repositories and direct fetches fromdevelopers.openai.com(SKILL.md). - Boundary markers: None explicitly defined; the agent is expected to parse the fetched documentation directly.
- Capability inventory: The skill uses
Read,Write,Edit,Bash,Grep,Glob,WebSearch, andWebFetch(SKILL.md). - Sanitization: No specific sanitization or validation logic is defined for the fetched content.
- [EXTERNAL_DOWNLOADS]: The skill fetches documentation from OpenAI's developer portal and searches for community-driven RFCs on GitHub. These operations target well-known and contextually relevant services.
Audit Metadata