ap2-risk-signals

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions specify fetching live documentation from https://ap2-protocol.org/ap2/specification/ and https://ap2-protocol.org/ap2/security_and_privacy_considerations/. This is used to inform the implementation of the risk framework.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection by fetching and processing untrusted external data from the web.
  • Ingestion points: Documentation URLs and web search results specified in SKILL.md.
  • Boundary markers: No explicit delimiters or warnings to ignore embedded instructions are present for the fetched content.
  • Capability inventory: The skill is configured with Write, Edit, and Bash tools, allowing file system modification and command execution based on processed data.
  • Sanitization: No sanitization or validation of the external content is performed before it enters the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM