ucp-conformance
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to clone the repository
https://github.com/Universal-Commerce-Protocol/conformanceto obtain the latest test suite. - [COMMAND_EXECUTION]: The instructions provide shell commands to synchronize dependencies (
uv sync) and execute Python test scripts (uv run checkout_lifecycle_test.py), which involves running code from the externally downloaded repository. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch instructions and test data from external sources via
WebSearchandWebFetch, creating an attack surface where untrusted data could influence agent behavior. - Ingestion points: Retrieves the README and current setup instructions from the GitHub repository at runtime.
- Boundary markers: Absent; there are no instructions to delimit or treat the fetched content as untrusted data.
- Capability inventory: The skill allows the use of powerful tools including
Bash,Write, andEditwhich could be abused if malicious instructions are ingested. - Sanitization: No sanitization or validation of the fetched external content is specified before the agent acts upon it.
Audit Metadata