ap2-payment-mandate

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch live protocol specifications and conceptual documentation from ap2-protocol.org. It also performs web searches for type definitions on GitHub.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external websites to guide the implementation of payment authorization flows. If the content of these external resources is compromised, it could influence the agent's code generation or command execution.
  • Ingestion points: ap2-protocol.org/ap2/specification/ and ap2-protocol.org/overview/ (referenced in SKILL.md)
  • Boundary markers: Absent; the agent is directed to use the fetched documentation directly.
  • Capability inventory: Write, Edit, Bash, and WebFetch tools are available to the agent.
  • Sanitization: Absent; there is no validation or filtering of the content retrieved from external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:32 PM