ap2-cryptographic-signing

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to fetch documentation from an external domain (ap2-protocol.org) and implement logic based on the retrieved content, creating a surface for indirect prompt injection. * Ingestion points: WebFetch calls to ap2-protocol.org for signing and checkout specifications in SKILL.md. * Boundary markers: Absent; there are no instructions to delimit or ignore instructions that might be embedded in the fetched content. * Capability inventory: The agent has access to Write, Edit, and Bash tools, which could be used to execute or persist malicious code if influenced by the external documentation. * Sanitization: Absent; no validation or sanitization of the external content is mandated before it is used to guide code implementation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:32 PM