commerce-protocol-readiness

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill evaluates external protocol signals and manifests which constitutes a data ingestion surface. This is addressed by a robust verification framework.
  • Ingestion points: Audit of UCP profiles, Agent Cards, and API catalogs.
  • Boundary markers: Explicit instructions to audit trust before action and never infer authority from identity.
  • Capability inventory: Guidelines cover discovery, checkout, and payment readiness.
  • Sanitization: Requirements for state recalculation and signature verification mitigate risks from untrusted data.
  • [SAFE]: The skill provides defensive guidelines and does not contain any executable code, remote downloads, or malicious patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 12:14 PM
Security Audit — agent-trust-hub — commerce-protocol-readiness