a11y-core

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes JSON data from audit findings and interpolates it into Markdown reports. This creates a surface where content from external findings files is rendered into documentation.
  • Ingestion points: scripts/merge-findings.mjs and scripts/render-report.mjs read findings payloads from the local filesystem.
  • Boundary markers: The reporting templates do not use specific boundary markers or instructions to ignore instructions embedded in the findings data.
  • Capability inventory: The render-report.mjs script can write generated reports to the filesystem using fs.writeFileSync.
  • Sanitization: Basic character escaping is performed to maintain Markdown table structure.
  • [DYNAMIC_EXECUTION]: The scripts/measure-context.mjs utility script uses dynamic import() to load local hook scripts for the purpose of estimating their token usage. This is a maintenance function that operates on files within the project repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 11:57 PM