ucp-ap2-mandates

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch protocol specifications and conceptual documentation from external domains including ucp.dev and ap2-protocol.org. It also directs the agent to a conformance test suite hosted at github.com/Universal-Commerce-Protocol/conformance.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources and uses it to perform sensitive operations like code implementation and testing.
  • Ingestion points: Documentation and schema files are retrieved via WebFetch from ucp.dev and ap2-protocol.org as specified in SKILL.md.
  • Boundary markers: The skill lacks instructions for the agent to treat fetched external data as untrusted or to isolate it from its primary instruction set.
  • Capability inventory: The agent has access to Bash, Write, and Edit tools, which could be leveraged if the external specifications contain malicious payloads designed to exploit the agent's autonomy.
  • Sanitization: There is no mechanism described for validating or sanitizing the external data before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:34 PM