acp-affiliate-attribution

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill's primary function is to guide the implementation of a privacy-focused attribution protocol.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an ingestion surface for external data by instructing the agent to fetch documentation and schemas.
  • Ingestion points: Results from WebSearch for GitHub repositories and direct fetches from developers.openai.com (SKILL.md).
  • Boundary markers: None explicitly defined; the agent is expected to parse the fetched documentation directly.
  • Capability inventory: The skill uses Read, Write, Edit, Bash, Grep, Glob, WebSearch, and WebFetch (SKILL.md).
  • Sanitization: No specific sanitization or validation logic is defined for the fetched content.
  • [EXTERNAL_DOWNLOADS]: The skill fetches documentation from OpenAI's developer portal and searches for community-driven RFCs on GitHub. These operations target well-known and contextually relevant services.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:32 PM