ucp-checkout-a2a

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download and review reference implementations and specifications from external sources that are not verified.
  • Evidence:
  • Fetches sample code from https://github.com/Universal-Commerce-Protocol/samples.
  • Fetches live specifications from ucp.dev using WebFetch.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could contain malicious instructions designed to manipulate the agent's behavior during checkout flows.
  • Ingestion points: WebFetch of specifications from ucp.dev and processing of structured messages (TextPart/DataPart) from external Business agents via the A2A protocol.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are defined for the fetched specs or incoming A2A messages.
  • Capability inventory: The skill allows Bash command execution, Write/Edit for file system modification, and WebFetch for further network operations.
  • Sanitization: The instructions do not specify any validation or sanitization steps for the data retrieved from external agents or specifications before processing.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 06:33 PM