a11y-core
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes JSON data from audit findings and interpolates it into Markdown reports. This creates a surface where content from external findings files is rendered into documentation.
- Ingestion points:
scripts/merge-findings.mjsandscripts/render-report.mjsread findings payloads from the local filesystem. - Boundary markers: The reporting templates do not use specific boundary markers or instructions to ignore instructions embedded in the findings data.
- Capability inventory: The
render-report.mjsscript can write generated reports to the filesystem usingfs.writeFileSync. - Sanitization: Basic character escaping is performed to maintain Markdown table structure.
- [DYNAMIC_EXECUTION]: The
scripts/measure-context.mjsutility script uses dynamicimport()to load local hook scripts for the purpose of estimating their token usage. This is a maintenance function that operates on files within the project repository.
Audit Metadata