a11y-audit
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides tools for accessibility auditing using local Python scripts that do not require external dependencies beyond the standard library.
- [SAFE]: No network activity, data exfiltration, or persistence mechanisms were detected in the skill code.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided HTML and CSS files, which could contain instructions intended to influence the agent when it reviews the tool's findings.
- Ingestion points: HTML and CSS files read by a11y_scanner.py and contrast_checker.py.
- Boundary markers: The scripts produce structured output with clear headers and field labels, separating the analyzed content from the report itself.
- Capability inventory: The skill is restricted to local file reads and standard output; it possesses no network, subprocess execution, or administrative capabilities.
- Sanitization: Content extracted from analyzed files is reported directly without specific filtering for prompt injection patterns.
Audit Metadata