accessibility
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's core workflow involves the agent ingesting and analyzing content from external, potentially untrusted web pages and the output of automated tools (like Lighthouse and axe-core). This represents a surface for indirect prompt injection where malicious content embedded in a target page could attempt to influence the agent's code-fixing suggestions or overall behavior.
- Ingestion points: The skill utilizes
lighthouse_audit,take_snapshot, and theaxeCLI to fetch and analyze external web content as described inSKILL.mdunder the 'Evidence-led audit workflow'. - Boundary markers: The instructions do not define specific delimiters or explicit 'ignore embedded instructions' warnings for the content being audited.
- Capability inventory: The skill expects the agent to modify the source code ('Fix the source') and perform network operations using CLI tools (
axe,lighthouse). - Sanitization: There is no evidence of specific sanitization, filtering, or validation of the data retrieved from external sources before it is processed by the agent.
Audit Metadata