Skip to content
Back to skills

Ucp Conformance

ASecurity

Run and write UCP conformance tests — validate a UCP implementation against the official test suite covering checkout lifecycle, orders, fulfillment, payments, idempotency, webhooks, and security. Use when testing or validating a UCP implementation.

  • 39 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 7, 2026
ai-agentsgobashtestinggitci/cdsecurity

Works with

  • cli
  • mcp

Security analysis

A100/100

Scanned September 7, 2026

npx -y skills add OrcaQubits/agentic-commerce-skills-plugins --skill ucp-conformance --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ucp Conformance?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Ucp Conformance
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/orcaqubits-ucp-conformance-agentic-commerce-skills-plugin/badge)](https://www.skillsdirectory.com/skills/orcaqubits-ucp-conformance-agentic-commerce-skills-plugin)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: ucp-conformance
description: >
  Run and write UCP conformance tests — validate a UCP implementation against
  the official test suite covering checkout lifecycle, orders, fulfillment,
  payments, idempotency, webhooks, and security. Use when testing or validating
  a UCP implementation.
---

# UCP Conformance Testing

## Before running tests

**Fetch the latest test suite**: Web-search `github Universal-Commerce-Protocol conformance` and fetch the README for current setup instructions, test data format, and CLI flags.

Repository: https://github.com/Universal-Commerce-Protocol/conformance

## Conceptual Architecture

### What the Conformance Suite Tests

The official suite contains ~13 test files covering:

| Test File | What It Validates |
|-----------|-------------------|
| Checkout lifecycle | Full create → update → complete → verify flow |
| Order management | Order creation, status transitions, data integrity |
| Fulfillment | Shipping/pickup methods, group selection, option validation |
| Card credentials | Payment credential format, tokenization |
| Webhooks | Delivery, retry, signature verification |
| Idempotency | Duplicate request handling, cache behavior |
| Invalid input | Error responses for malformed requests |
| Protocol compliance | Headers, TLS, version negotiation |
| Data validation | Schema compliance, required fields, type correctness |
| Service bindings | REST/MCP/A2A transport correctness |
| Business logic | Totals calculation, tax, discount application |
| AP2 integration | Mandate generation, signing, verification |
| Security (simulation URLs) | URL validation, injection prevention |

### How to Run

1. Clone the conformance repo
2. Install dependencies with `uv sync`
3. Start your UCP server locally
4. Run tests pointing at your server:

```bash
uv run checkout_lifecycle_test.py \
  --server_url=http://localhost:8182 \
  --simulation_secret=your-secret \
  --conformance_input=test_data/your_store/conformance_input.json
```

### Test Data

Tests require a `conformance_input.json` file that describes your store's products, prices, and expected behaviors. Check the sample test data in the repo for the format.

### Writing Custom Conformance Tests

When extending UCP with custom capabilities:
1. Use the same test patterns as the official suite
2. Test capability negotiation (extension present/absent)
3. Test schema validation against your custom schemas
4. Test error cases specific to your extension
5. Test idempotency for all mutating operations

### Integration with CI/CD

- Run conformance tests as part of your CI pipeline
- Use the `--server_url` flag to point at staging environments
- Track test pass rates as a quality gate for deployments

Always fetch the latest test suite before running — new tests are added as the spec evolves.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…