ap2-shopping-agent

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill describes an orchestrator that ingests natural language user requests to drive transaction flows and interact with merchants.
  • Ingestion points: User natural language shopping requests and merchant-provided Checkout Mandates are processed by the agent.
  • Boundary markers: The instructions do not specify explicit delimiters or markers to separate untrusted user input from system instructions.
  • Capability inventory: The agent is granted access to high-privilege tools including Bash, Write, Edit, WebSearch, and WebFetch.
  • Sanitization: The skill recommends deterministic validation of mandates as a mitigation strategy against non-deterministic LLM behavior.
  • [EXTERNAL_DOWNLOADS]: The implementation instructions direct the user to fetch protocol specifications and reference code from external repositories.
  • Evidence: The skill references documentation at ap2-protocol.org and sample implementations in the google-agentic-commerce repository on GitHub. These sources are consistent with the skill's stated purpose of implementing the AP2 protocol.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM