webmcp-commerce-tools

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions direct the agent to fetch documentation and examples from developer.chrome.com. This is an official domain for a well-known service (Google) used here to retrieve legitimate development guidance.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to interact with external e-commerce websites to perform product searches, view details, and manage carts. This ingestion of untrusted external content represents a surface for indirect prompt injection attacks.
  • Ingestion points: Data retrieved from external retailers via searchProducts, viewProductDetails, and general web search/fetch tools.
  • Boundary markers: The skill does not explicitly define delimiters or specific 'ignore' instructions for the data it processes.
  • Capability inventory: The skill allows high-privilege tools including Bash, Write, and Edit alongside network capabilities.
  • Sanitization: There are no explicit sanitization or validation steps mentioned for the external content retrieved before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM