ucp-fulfillment
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses the WebFetch tool to retrieve technical specifications from an external domain (ucp.dev) and references a sample repository on GitHub (Universal-Commerce-Protocol/samples). These external resources are used as the primary source of truth for the fulfillment schema and logic implementation.
- [INDIRECT_PROMPT_INJECTION]: The skill implements a pattern that is vulnerable to indirect prompt injection by ingesting and acting upon untrusted external data.
- Ingestion points: The agent is instructed to fetch specification documents from the web using WebFetch and WebSearch.
- Boundary markers: No explicit delimiters or boundary markers are defined in the instructions to separate fetched data from agent instructions.
- Capability inventory: The skill is granted access to high-privilege tools including Write, Edit, and Bash, which could be leveraged if malicious instructions were present in the fetched documentation.
- Sanitization: The skill lacks any mechanism for sanitizing or validating the content retrieved from external sources before it is used to drive code generation and implementation tasks.
Audit Metadata