ap2-cryptographic-signing
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to fetch documentation from an external domain (
ap2-protocol.org) and implement logic based on the retrieved content, creating a surface for indirect prompt injection. * Ingestion points:WebFetchcalls toap2-protocol.orgfor signing and checkout specifications inSKILL.md. * Boundary markers: Absent; there are no instructions to delimit or ignore instructions that might be embedded in the fetched content. * Capability inventory: The agent has access toWrite,Edit, andBashtools, which could be used to execute or persist malicious code if influenced by the external documentation. * Sanitization: Absent; no validation or sanitization of the external content is mandated before it is used to guide code implementation.
Audit Metadata