qa-accessibility-test-writer

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest non-functional requirement (NFR) analysis from another skill to determine the scope of generated tests. This creates a reliance on external data, though the risk is minimized as the skill only generates code for user review and does not execute it.
  • Ingestion points: Processes accessibility criteria results from the qa-nfr-analyst skill (Workflow step 1).
  • Boundary markers: No specific delimiters or instructions to ignore potential instructions within the NFR data are defined.
  • Capability inventory: The skill writes test files to the tests/accessibility/ directory. It does not possess network or shell execution capabilities in its own context.
  • Sanitization: There is no evidence of input filtering or sanitization for the ingested criteria.
  • [DYNAMIC_EXECUTION]: The skill generates executable TypeScript and JavaScript test files based on patterns and success criteria defined in its reference documentation. This activity is the primary intended function of the skill and occurs in the output directory specified by the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:38 PM
Security Audit — agent-trust-hub — qa-accessibility-test-writer