acp-extensions-authoring
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch documentation from OpenAI's official developer portal and search GitHub for specific protocol RFCs and examples. These targets represent well-known and trusted services.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests untrusted data from the web and maintains powerful tool capabilities.
- Ingestion points: Content retrieved via
WebFetchfromdevelopers.openai.comandWebSearchresults fromgithub.com. - Boundary markers: Absent. The instructions do not include delimiters or warnings to ignore malicious instructions that might be embedded in the external documentation.
- Capability inventory: The skill has access to
Bashfor command execution andWrite/Editfor file system modifications. - Sanitization: Absent. There are no mechanisms described to validate or filter the content retrieved from external sources before it is processed by the agent.
Audit Metadata