keyboard-navigator

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill package is composed entirely of Markdown reference files, a YAML configuration, and a JSON example. There are no executable scripts, binaries, or automated tasks included.
  • [SAFE]: Analysis of the instructions and documentation confirms they are limited to accessibility best practices. No evidence of prompt injection, data exfiltration, obfuscation, or persistence mechanisms was found.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for analyzing untrusted external code (SKILL.md). Ingestion point: Reviewing target application source code for accessibility issues. Boundary markers: Absent. Capability inventory: None (the skill includes no scripts or tool usage). Sanitization: Absent. The risk is negligible as the skill lacks capabilities to execute or propagate malicious commands found in target data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 05:59 AM