ap2-mcp-server

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch live documentation and implementation considerations from ap2-protocol.org.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection because it ingests data from external sources.\n
  • Ingestion points: Instructions in SKILL.md direct the agent to fetch documentation from ap2-protocol.org and github.com.\n
  • Boundary markers: Absent. The skill does not provide delimiters or specific instructions to treat the fetched content as untrusted data.\n
  • Capability inventory: The skill's allowed-tools configuration includes Write, Bash, and WebFetch.\n
  • Sanitization: Absent. There is no evidence of validation or filtering for the content retrieved from external URLs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM