accessibility-engineer

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the dynamic context injection syntax (!cat ...) to load content from skills/_shared/protocols/ux-protocol.md and .production-grade.yaml when the skill is initialized. These operations are localized to reading project-specific configuration files and do not incorporate untrusted user input or perform network operations.
  • [SAFE]: The instructions primarily describe processes for accessibility testing, such as running audits (axe-core/Lighthouse), keyboard navigation checks, and screen reader verification. No obfuscation, credential exfiltration, or persistence mechanisms were detected.
  • [SAFE]: While the skill ingests external data (web pages and HTML source code) for auditing, it lacks high-privilege capabilities or instructions that would facilitate indirect prompt injection attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 07:28 PM
Security Audit — agent-trust-hub — accessibility-engineer