a11y-tool-builder
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to build tools that ingest and process external, untrusted document formats (HTML, DOCX, PDF) and desktop UI trees, which constitutes an indirect prompt injection attack surface.
- Ingestion points: Parsers for DOCX (python-docx), PDF (pikepdf, pdfplumber), and UIA trees (comtypes, pywinauto) as described in SKILL.md.
- Boundary markers: No specific delimiters or instructions to ignore embedded content within processed documents are mentioned.
- Capability inventory: The skill focuses on rule evaluation, report generation (Markdown, CSV, SARIF), and coordination with other specialists; it does not explicitly define high-privilege operations like arbitrary network access or system-wide file writes.
- Sanitization: The instructions do not specify sanitization or validation logic for the content extracted from processed documents.
Audit Metadata