ap2-intent-mandate

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to fetch and process documentation from external websites (ap2-protocol.org) and search results to guide its execution.
  • Ingestion points: Content is retrieved from external URLs using the WebFetch tool.
  • Capability inventory: The agent is configured with high-capability tools, including Bash, Write, and Edit.
  • Boundary markers: The instructions lack boundary markers or warnings to disregard potential instructions embedded within the fetched documentation.
  • Sanitization: No sanitization or validation of the external content is requested before the agent uses it to inform its actions.
  • [EXTERNAL_DOWNLOADS]: The skill fetches protocol documentation and terminology from ap2-protocol.org. These downloads are documented as necessary for the skill's primary purpose of implementing the AP2 Intent Mandate protocol.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:32 PM