acp-extensions-authoring

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch documentation from OpenAI's official developer portal and search GitHub for specific protocol RFCs and examples. These targets represent well-known and trusted services.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests untrusted data from the web and maintains powerful tool capabilities.
  • Ingestion points: Content retrieved via WebFetch from developers.openai.com and WebSearch results from github.com.
  • Boundary markers: Absent. The instructions do not include delimiters or warnings to ignore malicious instructions that might be embedded in the external documentation.
  • Capability inventory: The skill has access to Bash for command execution and Write/Edit for file system modifications.
  • Sanitization: Absent. There are no mechanisms described to validate or filter the content retrieved from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:32 PM