ucp-loyalty
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to fetch live specifications from ucp.dev using WebSearch and WebFetch. This introduces a potential surface where an external source could provide instructions that override agent behavior.
- Ingestion points: External content is fetched from ucp.dev (SKILL.md).
- Boundary markers: No delimiters or safety warnings are provided for processing this external data.
- Capability inventory: The agent possesses Write, Edit, and Bash tools which could be targeted by a potential injection attack.
- Sanitization: There is no requirement to validate or sanitize the external specification content.
- [EXTERNAL_DOWNLOADS]: The instructions reference a third-party GitHub repository (https://github.com/Universal-Commerce-Protocol/samples) for reference implementation code.
Audit Metadata