ap2-merchant-agent

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches protocol specifications and technical documentation from ap2-protocol.org and reference implementations from GitHub repositories.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external Intent Mandates from third-party Shopping Agents, which represents an untrusted data ingestion surface.
  • Ingestion points: Incoming Intent Mandates are parsed from external agents as described in SKILL.md.
  • Boundary markers: No specific delimiters are defined in the implementation guide for separating external instructions from agent prompts.
  • Capability inventory: The skill utilizes tools including Bash, Write, WebFetch, and Edit, which provide significant control over the environment.
  • Sanitization: The skill explicitly recommends implementing validation for incoming mandates to ensure authenticity and integrity.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM