agent-interop
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The documentation identifies potential attack surfaces when agents ingest untrusted data from external tool outputs or peer agents.
- Ingestion points: Described in
references/mcp.md(resource reading) andreferences/a2a.md(message turns). - Boundary markers: The skill explicitly mandates treating all external output as untrusted input and recommends human-in-the-loop consent.
- Capability inventory: The guidelines cover tool execution and programmatic code execution architectures.
- Sanitization: The documentation provides reference implementations for authentication middleware and advises on output filtering and truncation.
- [EXTERNAL_DOWNLOADS]: Fetches official utilities from well-known GitHub repositories.
- Evidence:
references/registry.mdprovides a command to download themcp-publisherbinary from the official Model Context Protocol organization on GitHub. - [DYNAMIC_EXECUTION]: Outlines secure architectures for runtime code generation and execution.
- Evidence:
references/mcp-scale.mddescribes 'code mode' where models generate scripts to process data, providing detailed requirements for network isolation, resource limits, and per-call authorization within sandboxes.
Audit Metadata