ucp-ap2-mandates
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch protocol specifications and conceptual documentation from external domains including
ucp.devandap2-protocol.org. It also directs the agent to a conformance test suite hosted atgithub.com/Universal-Commerce-Protocol/conformance. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources and uses it to perform sensitive operations like code implementation and testing.
- Ingestion points: Documentation and schema files are retrieved via
WebFetchfromucp.devandap2-protocol.orgas specified inSKILL.md. - Boundary markers: The skill lacks instructions for the agent to treat fetched external data as untrusted or to isolate it from its primary instruction set.
- Capability inventory: The agent has access to
Bash,Write, andEdittools, which could be leveraged if the external specifications contain malicious payloads designed to exploit the agent's autonomy. - Sanitization: There is no mechanism described for validating or sanitizing the external data before the agent processes it.
Audit Metadata