acp-intent-traces
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to fetch and search for external documentation, which could potentially contain malicious instructions intended to influence the agent's behavior.
- Ingestion points: Retrieval of RFCs and JSON schemas via
WebSearchandWebFetchtools from external sources as specified in the "Before writing code" section. - Boundary markers: The instructions lack specific delimiters or warnings to prevent the agent from following instructions embedded within the fetched documentation.
- Capability inventory: The skill environment allows use of
Bash,Write,Edit, andReadtools. - Sanitization: No validation or sanitization of the retrieved external content is specified before the agent processes it.
- [EXTERNAL_DOWNLOADS]: Fetches configuration and specification details from OpenAI's developer site and searches GitHub for relevant protocol documentation.
Audit Metadata