acp-setup

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches OpenAPI specifications from the Agentic Commerce Protocol's GitHub repository and documentation from OpenAI's developer portal. These resources are specific to the skill's primary function of scaffolding a protocol-compliant server.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external web sources and repositories to generate code stubs and configuration.
  • Ingestion points: Ingests content from GitHub repositories and OpenAI documentation via WebFetch and WebSearch tools in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the fetched YAML specs.
  • Capability inventory: The skill utilizes Write for file generation and Bash for project initialization.
  • Sanitization: No explicit validation or sanitization steps are defined for the content of the external OpenAPI specifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM