mpp-service-discovery

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to fetch and process data from external domains (paymentauth.org, mpp.dev) and perform web searches to find implementation examples. This untrusted content is used to guide the agent's code implementation, creating a surface where malicious instructions embedded in external resources could influence the agent's behavior.
  • Ingestion points: https://paymentauth.org/, https://mpp.dev/overview, and web search result snippets for MPP service discovery.
  • Boundary markers: Absent. The instructions do not specify any delimiters or warnings to ignore instructions within the fetched data.
  • Capability inventory: The skill has access to sensitive tools including Write, Edit, and Bash, which could be abused if the agent obeys malicious instructions from external sources.
  • Sanitization: No sanitization or validation of the external content is performed before it is processed by the agent.
  • [DATA_EXFILTRATION]: The skill performs network operations to non-whitelisted external domains (paymentauth.org, mpp.dev) using WebFetch to retrieve protocol specifications and documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM