wcag-aaa
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core function of auditing external web content. 1. Ingestion points: The Audit Process section directs the agent to Read targets which involves processing untrusted external web content. 2. Boundary markers: No delimiters or specific instructions are provided to the agent to disregard instructions found within the audited content. 3. Capability inventory: The skill utilizes tools to retrieve and analyze external HTML/web content. 4. Sanitization: No sanitization or validation of the input content is specified.
- [EXTERNAL_DOWNLOADS]: The skill references authoritative WCAG documentation from the World Wide Web Consortium (W3C). Evidence: Links to w3.org are provided for reference purposes. Assessment: These links point to a well-known standards organization and do not involve executable code downloads.
Audit Metadata