keyboard-navigator
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [NO_CODE]: The skill package is composed entirely of Markdown reference files, a YAML configuration, and a JSON example. There are no executable scripts, binaries, or automated tasks included.
- [SAFE]: Analysis of the instructions and documentation confirms they are limited to accessibility best practices. No evidence of prompt injection, data exfiltration, obfuscation, or persistence mechanisms was found.
- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for analyzing untrusted external code (SKILL.md). Ingestion point: Reviewing target application source code for accessibility issues. Boundary markers: Absent. Capability inventory: None (the skill includes no scripts or tool usage). Sanitization: Absent. The risk is negligible as the skill lacks capabilities to execute or propagate malicious commands found in target data.
Audit Metadata