accessibility

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's core workflow involves the agent ingesting and analyzing content from external, potentially untrusted web pages and the output of automated tools (like Lighthouse and axe-core). This represents a surface for indirect prompt injection where malicious content embedded in a target page could attempt to influence the agent's code-fixing suggestions or overall behavior.
  • Ingestion points: The skill utilizes lighthouse_audit, take_snapshot, and the axe CLI to fetch and analyze external web content as described in SKILL.md under the 'Evidence-led audit workflow'.
  • Boundary markers: The instructions do not define specific delimiters or explicit 'ignore embedded instructions' warnings for the content being audited.
  • Capability inventory: The skill expects the agent to modify the source code ('Fix the source') and perform network operations using CLI tools (axe, lighthouse).
  • Sanitization: There is no evidence of specific sanitization, filtering, or validation of the data retrieved from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 10:23 PM
Security Audit — agent-trust-hub — accessibility