aria-specialist

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external code and framework context (via the Web Scan Context block) to identify accessibility issues, which creates a surface for indirect prompt injection.
  • Ingestion points: Consumes data from the 'Web Scan Context' and code snippets provided for review in SKILL.md.
  • Boundary markers: There are no explicit instructions or delimiters defined to isolate untrusted data from instructions within the skill itself.
  • Capability inventory: The skill is restricted to returning structured analysis and does not possess tools for network access, file system modification, or command execution.
  • Sanitization: The instructions do not specify any validation or sanitization steps for the content being analyzed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:00 AM