ucp-conformance

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to clone the repository https://github.com/Universal-Commerce-Protocol/conformance to obtain the latest test suite.
  • [COMMAND_EXECUTION]: The instructions provide shell commands to synchronize dependencies (uv sync) and execute Python test scripts (uv run checkout_lifecycle_test.py), which involves running code from the externally downloaded repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch instructions and test data from external sources via WebSearch and WebFetch, creating an attack surface where untrusted data could influence agent behavior.
  • Ingestion points: Retrieves the README and current setup instructions from the GitHub repository at runtime.
  • Boundary markers: Absent; there are no instructions to delimit or treat the fetched content as untrusted data.
  • Capability inventory: The skill allows the use of powerful tools including Bash, Write, and Edit which could be abused if malicious instructions are ingested.
  • Sanitization: No sanitization or validation of the fetched external content is specified before the agent acts upon it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM