ucp-catalog

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to use WebSearch and WebFetch to retrieve live specifications and schemas from ucp.dev and general web results. This ingestion of untrusted external content into the agent's context creates a potential attack surface.
  • Ingestion points: External capability and operation pages fetched via WebSearch and WebFetch as instructed in the 'Before writing code' section of SKILL.md.
  • Boundary markers: The instructions do not specify any delimiters or warnings for the agent to ignore potentially malicious instructions embedded in the external documentation.
  • Capability inventory: The skill allows the use of Write, Edit, and Bash tools, which could be misused if the agent follows instructions hidden within the fetched data.
  • Sanitization: There are no requirements for sanitizing or validating the content retrieved from external URLs.
  • [EXTERNAL_DOWNLOADS]: The skill provides a link to a reference implementation at https://github.com/Universal-Commerce-Protocol/samples. This is documented as a resource for the developer and does not involve automated execution or installation by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM