web-accessibility

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill contains a hardcoded absolute file path /Users/taylorarndt/.agents/skills/web-accessibility/SKILL.md which discloses a local system username.\n- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it ingests data from local configuration and reference files to determine its execution logic.\n
  • Ingestion points: The agent is instructed to read contents from codex-plugin/references/specialists/accessibility-lead.md, codex-plugin/references/specialists/index.json, and search for extension manifests under .a11y-agents/extensions/ and ~/.a11y-agents/extensions/.\n
  • Boundary markers: Absent. No instructions are provided to the agent to isolate or ignore potential instructions embedded within these external files.\n
  • Capability inventory: The skill utilizes the tool_search and multi_agent_v1.spawn_agent tools to dynamically discover and execute subagents based on the data read from the local files.\n
  • Sanitization: Absent. There is no evidence of validation or filtering of the content read from these local paths before it influences the agent's behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 09:27 AM
Security Audit — agent-trust-hub — web-accessibility