ucp-checkout-a2a
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download and review reference implementations and specifications from external sources that are not verified.
- Evidence:
- Fetches sample code from
https://github.com/Universal-Commerce-Protocol/samples. - Fetches live specifications from
ucp.devusingWebFetch. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could contain malicious instructions designed to manipulate the agent's behavior during checkout flows.
- Ingestion points:
WebFetchof specifications fromucp.devand processing of structured messages (TextPart/DataPart) from external Business agents via the A2A protocol. - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are defined for the fetched specs or incoming A2A messages.
- Capability inventory: The skill allows
Bashcommand execution,Write/Editfor file system modification, andWebFetchfor further network operations. - Sanitization: The instructions do not specify any validation or sanitization steps for the data retrieved from external agents or specifications before processing.
Audit Metadata