a11y-tool-builder

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to build tools that ingest and process external, untrusted document formats (HTML, DOCX, PDF) and desktop UI trees, which constitutes an indirect prompt injection attack surface.
  • Ingestion points: Parsers for DOCX (python-docx), PDF (pikepdf, pdfplumber), and UIA trees (comtypes, pywinauto) as described in SKILL.md.
  • Boundary markers: No specific delimiters or instructions to ignore embedded content within processed documents are mentioned.
  • Capability inventory: The skill focuses on rule evaluation, report generation (Markdown, CSV, SARIF), and coordination with other specialists; it does not explicitly define high-privilege operations like arbitrary network access or system-wide file writes.
  • Sanitization: The instructions do not specify sanitization or validation logic for the content extracted from processed documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 05:59 AM