mpp-conformance
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches the canonical MPP specification from
paymentauth.organd the IETF draft fromdatatracker.ietf.org. It also suggest fetching documentation from Stripe to verify production readiness. - [INDIRECT_PROMPT_INJECTION]: The skill ingests documentation from external sources to guide the validation process.
- Ingestion points: Specification documents from
paymentauth.organd IETF draft pages referenced in SKILL.md. - Boundary markers: None present in the instructions.
- Capability inventory: The skill uses a broad set of tools including
Bash,Write, andWebFetchas defined in the frontmatter. - Sanitization: No explicit sanitization or filtering of the fetched documentation is specified.
Audit Metadata