ucp-buyer-consent

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to fetch live specifications from ucp.dev and perform web searches to inform code implementation, which introduces a surface for indirect prompt injection from those external sources.
  • Ingestion points: Fetching from ucp.dev/specification/ and web searching github.com/Universal-Commerce-Protocol.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to treat fetched data as untrusted.
  • Capability inventory: No executable tools are defined in the frontmatter; the skill focuses on documentation and manual implementation.
  • Sanitization: No sanitization or validation of external content is requested.
  • [NO_CODE]: This skill contains no executable scripts, binaries, or command-line operations, significantly reducing the direct execution risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM