ucp-setup
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches protocol specifications, sample architectures, and SDK documentation from non-trusted external domains and GitHub repositories, including
ucp.devandgithub.com/Universal-Commerce-Protocol. - [REMOTE_CODE_EXECUTION]: Instructs the agent to clone the
python-sdkrepository and executeuv sync. This pattern involves downloading and executing environment configurations and dependencies defined in a remote repository belonging to an unverified source. - [COMMAND_EXECUTION]: The skill guides the agent to install dependencies from public registries using
pipandnpm. Specifically, it points to the community-maintainedfastucp-pythonpackage and the@ucp-js/sdkpackage, which are not verified by the skill author as official. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to instructions embedded in external data it processes during the scaffolding phase.
- Ingestion points: Fetches content from external READMEs, spec overviews, and web search results to guide project generation.
- Boundary markers: There are no instructions or delimiters provided to ensure the agent ignores or isolates potentially malicious instructions embedded in these external sources.
- Capability inventory: The skill has access to
Bash(for installations),Write(for file creation), andEdittools. - Sanitization: No validation or filtering is performed on the fetched documentation before the agent uses it to define the project structure and logic.
Audit Metadata