ucp-checkout-rest
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to fetch external technical specifications through web searches and external domains to define its implementation logic.
- Ingestion points: Specification details are ingested via
WebSearchandWebFetchtools fromucp.devand generic search results as instructed in the "Before writing code" section. - Boundary markers: There are no explicit boundary markers or instructions to treat the fetched content as untrusted data or to ignore embedded instructions.
- Capability inventory: The agent has access to
Bash,Write, andEdit, which could be exploited if the fetched specifications contain adversarial instructions. - Sanitization: No sanitization or verification of the fetched external content is performed before it is integrated into the agent's reasoning.
- [INDIRECT_PROMPT_INJECTION]: The protocol implementation involves fetching platform profiles from URIs provided in the
UCP-Agentrequest header. - Ingestion points: External profile URIs are extracted from incoming HTTP headers provided by potentially untrusted clients.
- Boundary markers: None present.
- Capability inventory: The agent uses
WebFetchto retrieve these profiles, and the resulting data influences the business logic implemented viaBashand file tools. - Sanitization: The skill does not provide mechanisms for validating or restricting the domains of the profile URIs.
- [DATA_EXFILTRATION]: The skill initiates network operations to
ucp.devand performs broad web searches to retrieve external resources. - Evidence: Instructions include fetching from
https://ucp.dev/latest/specification/reference/and performing web searches for endpoint shapes and schemas.
Audit Metadata