a11y
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No patterns for overriding agent behavior or bypassing safety filters were detected.
- [DATA_EXFILTRATION]: No evidence of hardcoded credentials, sensitive file access, or unauthorized network exfiltration was found. The
WebFetchtool is used legitimately for dynamic accessibility passes against user-supplied URLs. - [REMOTE_CODE_EXECUTION]: No remote script downloads or dynamic execution patterns were detected. The skill references
axe-coreandchrome-devtoolsas tools for analysis rather than executing arbitrary remote code. - [COMMAND_EXECUTION]: The skill uses localized tools like
Bash,Grep, andTaskto perform source code audits, which is appropriate for its stated purpose of accessibility checking. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted source files and external web content, which constitutes an indirect prompt injection surface. However, the risk is minimal as the skill is focused on reporting defects rather than executing logic based on the content of those files.
Audit Metadata