web-accessibility-wizard
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONPERSISTENCEDYNAMIC_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill downloads and executes several external packages from the NPM registry at runtime using
npx. This includes@axe-core/clifor accessibility scanning andcapture-website-clifor screenshot generation. These are well-known tools from a trusted public registry. - [COMMAND_EXECUTION]: The skill executes shell commands to run local scripts (e.g.,
node skills/a11y-core/scripts/render-report.mjs), invoke external CLI tools, and create directories or files for reports and screenshots. - [DATA_EXFILTRATION]: During the discovery phase (Phase 0), the skill silently probes the local network for common development server ports (3000, 5173, 8080, 4200, 8000) to detect running applications. While this is performed for discovery purposes, it constitutes a local network scanning capability.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external web pages and source code files during the audit process. This represents a vulnerability surface where malicious instructions embedded in the audited content could potentially influence the agent's behavior.
- Ingestion points: Reads source code and rendered HTML from user-provided URLs (SKILL.md, phase-0-discovery.md).
- Boundary markers: Includes instructions to specialists to focus on specific tasks and use structured JSON findings, but lacks explicit delimiters for the ingested HTML data.
- Capability inventory: Can write files (reports), execute shell commands (npx, node), and delegate tasks to multiple specialist agents (SKILL.md).
- Sanitization: No specific sanitization or filtering of the external HTML content is described before processing.
- [PERSISTENCE]: The skill can generate and write CI/CD configuration files, such as GitHub Actions (
.github/workflows/web-accessibility.yml) and Azure DevOps pipelines. This allows the audit functionality to persist and run automatically in the project's development environment. - [DYNAMIC_EXECUTION]: The skill supports an 'Interactive Fix Mode' where it generates code fixes based on audit findings and applies them to the source files upon user confirmation. It also uses string concatenation to assemble command paths for report rendering.
Audit Metadata