mpp-dev-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to retrieve and process content from external sources, which could lead to indirect prompt injection if the source content contains malicious instructions.
- Ingestion points:
SKILL.mdinstructs the agent to fetch protocol requirements and documentation fromhttps://paymentauth.org/,https://docs.stripe.com/payments/machine/mpp, and IETF drafts usingWebFetchandWebSearch. - Boundary markers: The skill does not provide delimiters or instructions to the agent to treat the fetched content as untrusted data or to ignore embedded instructions.
- Capability inventory: The agent's access to
Write,Edit, andBashtools increases the risk if it follows malicious instructions found in external content. - Sanitization: There is no evidence of sanitization, validation, or filtering of the external documentation before it is processed by the agent.
Audit Metadata