ucp-buyer-consent
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to fetch live specifications from ucp.dev and perform web searches to inform code implementation, which introduces a surface for indirect prompt injection from those external sources.
- Ingestion points: Fetching from ucp.dev/specification/ and web searching github.com/Universal-Commerce-Protocol.
- Boundary markers: No explicit delimiters or instructions are provided to the agent to treat fetched data as untrusted.
- Capability inventory: No executable tools are defined in the frontmatter; the skill focuses on documentation and manual implementation.
- Sanitization: No sanitization or validation of external content is requested.
- [NO_CODE]: This skill contains no executable scripts, binaries, or command-line operations, significantly reducing the direct execution risk.
Audit Metadata