webmcp-commerce-tools
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions direct the agent to fetch documentation and examples from
developer.chrome.com. This is an official domain for a well-known service (Google) used here to retrieve legitimate development guidance. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to interact with external e-commerce websites to perform product searches, view details, and manage carts. This ingestion of untrusted external content represents a surface for indirect prompt injection attacks.
- Ingestion points: Data retrieved from external retailers via
searchProducts,viewProductDetails, and general web search/fetch tools. - Boundary markers: The skill does not explicitly define delimiters or specific 'ignore' instructions for the data it processes.
- Capability inventory: The skill allows high-privilege tools including
Bash,Write, andEditalongside network capabilities. - Sanitization: There are no explicit sanitization or validation steps mentioned for the external content retrieved before it is processed by the agent.
Audit Metadata