accessibility-engineer
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the dynamic context injection syntax (
!cat ...) to load content fromskills/_shared/protocols/ux-protocol.mdand.production-grade.yamlwhen the skill is initialized. These operations are localized to reading project-specific configuration files and do not incorporate untrusted user input or perform network operations. - [SAFE]: The instructions primarily describe processes for accessibility testing, such as running audits (axe-core/Lighthouse), keyboard navigation checks, and screen reader verification. No obfuscation, credential exfiltration, or persistence mechanisms were detected.
- [SAFE]: While the skill ingests external data (web pages and HTML source code) for auditing, it lacks high-privilege capabilities or instructions that would facilitate indirect prompt injection attacks.
Audit Metadata