ap2-payment-mandate
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch live protocol specifications and conceptual documentation from
ap2-protocol.org. It also performs web searches for type definitions on GitHub. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external websites to guide the implementation of payment authorization flows. If the content of these external resources is compromised, it could influence the agent's code generation or command execution.
- Ingestion points:
ap2-protocol.org/ap2/specification/andap2-protocol.org/overview/(referenced in SKILL.md) - Boundary markers: Absent; the agent is directed to use the fetched documentation directly.
- Capability inventory:
Write,Edit,Bash, andWebFetchtools are available to the agent. - Sanitization: Absent; there is no validation or filtering of the content retrieved from external sources.
Audit Metadata