ucp-fulfillment

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses the WebFetch tool to retrieve technical specifications from an external domain (ucp.dev) and references a sample repository on GitHub (Universal-Commerce-Protocol/samples). These external resources are used as the primary source of truth for the fulfillment schema and logic implementation.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a pattern that is vulnerable to indirect prompt injection by ingesting and acting upon untrusted external data.
  • Ingestion points: The agent is instructed to fetch specification documents from the web using WebFetch and WebSearch.
  • Boundary markers: No explicit delimiters or boundary markers are defined in the instructions to separate fetched data from agent instructions.
  • Capability inventory: The skill is granted access to high-privilege tools including Write, Edit, and Bash, which could be leveraged if malicious instructions were present in the fetched documentation.
  • Sanitization: The skill lacks any mechanism for sanitizing or validating the content retrieved from external sources before it is used to drive code generation and implementation tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM