ucp-checkout-rest

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to fetch external technical specifications through web searches and external domains to define its implementation logic.
  • Ingestion points: Specification details are ingested via WebSearch and WebFetch tools from ucp.dev and generic search results as instructed in the "Before writing code" section.
  • Boundary markers: There are no explicit boundary markers or instructions to treat the fetched content as untrusted data or to ignore embedded instructions.
  • Capability inventory: The agent has access to Bash, Write, and Edit, which could be exploited if the fetched specifications contain adversarial instructions.
  • Sanitization: No sanitization or verification of the fetched external content is performed before it is integrated into the agent's reasoning.
  • [INDIRECT_PROMPT_INJECTION]: The protocol implementation involves fetching platform profiles from URIs provided in the UCP-Agent request header.
  • Ingestion points: External profile URIs are extracted from incoming HTTP headers provided by potentially untrusted clients.
  • Boundary markers: None present.
  • Capability inventory: The agent uses WebFetch to retrieve these profiles, and the resulting data influences the business logic implemented via Bash and file tools.
  • Sanitization: The skill does not provide mechanisms for validating or restricting the domains of the profile URIs.
  • [DATA_EXFILTRATION]: The skill initiates network operations to ucp.dev and performs broad web searches to retrieve external resources.
  • Evidence: Instructions include fetching from https://ucp.dev/latest/specification/reference/ and performing web searches for endpoint shapes and schemas.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:34 PM