ucp-cart
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches a JSON schema from https://ucp.dev/latest/schemas/shopping/cart.json and instructs the agent to search for specifications on ucp.dev. These references are to the official protocol domain.
- [INDIRECT_PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection by fetching external specifications and schemas which are then used to drive code generation and execution.
- Ingestion points: WebSearch and WebFetch operations targeting ucp.dev as defined in SKILL.md.
- Boundary markers: Absent.
- Capability inventory: Write, Edit, and Bash tools are enabled in SKILL.md, allowing the agent to modify the file system and execute shell commands based on the external input.
- Sanitization: Absent.
- [COMMAND_EXECUTION]: The skill enables the Bash tool, which allows for shell command execution. This is a standard capability for implementation tasks but increases the impact of potential injections.
Audit Metadata