acp-delegate-authentication
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to fetch external OpenAPI and JSON schema files to determine API paths, request fields, and logic. This constitutes an attack surface where malicious content in the external repository could influence agent behavior. \n
- Ingestion points: Fetches data from https://github.com/agentic-commerce-protocol/agentic-commerce-protocol/releases and associated YAML/JSON files. \n
- Boundary markers: The skill does not provide clear boundaries or instructions to ignore embedded prompts within the external data. \n
- Capability inventory: The skill possesses extensive capabilities including Write, Bash, and WebFetch which could be misused if the agent is influenced by injected content. \n
- Sanitization: There is no evidence of validation or sanitization for the fetched specifications. \n- [EXTERNAL_DOWNLOADS]: The skill relies on downloading external technical documentation and schemas from a GitHub repository at runtime to perform its tasks.
Audit Metadata