a11y-audit
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: All instructions and scripts are consistent with the skill's stated purpose of providing accessibility auditing and remediation guidance. No attempts to bypass safety filters or perform unauthorized actions were detected.
- [DATA_EXPOSURE]: The skill uses Python scripts to analyze project source code. These scripts (
a11y_scanner.py,contrast_checker.py) perform read-only operations on local files provided by the user and do not access sensitive directories or transmit data to external servers. - [UNVERIFIABLE_DEPENDENCIES]: The provided scripts rely exclusively on the Python standard library, avoiding third-party dependency risks and remote package installation.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted frontend codebases (HTML, JSX, Vue, Svelte, etc.) to detect accessibility violations. This represents a functional attack surface where malicious comments in the scanned code could attempt to influence the agent. However, the risk is negligible as the skill lacks network access or execution capabilities for the processed code.
- Ingestion points: Local file system access via audit scripts to read source code files.
- Boundary markers: Not explicitly defined in the scanning logic.
- Capability inventory: Reading local files and writing reports to standard output or local files. No network operations or subprocess execution found.
- Sanitization: Not applicable for this static analysis tool.
- [OBFUSCATION]: The skill contains no obfuscated code, hidden characters, or encoded payloads. All logic and documentation are provided in clear, human-readable text.
Audit Metadata