ucp-setup

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches protocol specifications, sample architectures, and SDK documentation from non-trusted external domains and GitHub repositories, including ucp.dev and github.com/Universal-Commerce-Protocol.
  • [REMOTE_CODE_EXECUTION]: Instructs the agent to clone the python-sdk repository and execute uv sync. This pattern involves downloading and executing environment configurations and dependencies defined in a remote repository belonging to an unverified source.
  • [COMMAND_EXECUTION]: The skill guides the agent to install dependencies from public registries using pip and npm. Specifically, it points to the community-maintained fastucp-python package and the @ucp-js/sdk package, which are not verified by the skill author as official.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to instructions embedded in external data it processes during the scaffolding phase.
  • Ingestion points: Fetches content from external READMEs, spec overviews, and web search results to guide project generation.
  • Boundary markers: There are no instructions or delimiters provided to ensure the agent ignores or isolates potentially malicious instructions embedded in these external sources.
  • Capability inventory: The skill has access to Bash (for installations), Write (for file creation), and Edit tools.
  • Sanitization: No validation or filtering is performed on the fetched documentation before the agent uses it to define the project structure and logic.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 06:34 PM