ucp-catalog
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to use
WebSearchandWebFetchto retrieve live specifications and schemas fromucp.devand general web results. This ingestion of untrusted external content into the agent's context creates a potential attack surface. - Ingestion points: External capability and operation pages fetched via
WebSearchandWebFetchas instructed in the 'Before writing code' section ofSKILL.md. - Boundary markers: The instructions do not specify any delimiters or warnings for the agent to ignore potentially malicious instructions embedded in the external documentation.
- Capability inventory: The skill allows the use of
Write,Edit, andBashtools, which could be misused if the agent follows instructions hidden within the fetched data. - Sanitization: There are no requirements for sanitizing or validating the content retrieved from external URLs.
- [EXTERNAL_DOWNLOADS]: The skill provides a link to a reference implementation at
https://github.com/Universal-Commerce-Protocol/samples. This is documented as a resource for the developer and does not involve automated execution or installation by the agent.
Audit Metadata