web-accessibility
Pass
Audited by Gen Agent Trust Hub on Jun 25, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill contains a hardcoded absolute file path
/Users/taylorarndt/.agents/skills/web-accessibility/SKILL.mdwhich discloses a local system username.\n- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it ingests data from local configuration and reference files to determine its execution logic.\n - Ingestion points: The agent is instructed to read contents from
codex-plugin/references/specialists/accessibility-lead.md,codex-plugin/references/specialists/index.json, and search for extension manifests under.a11y-agents/extensions/and~/.a11y-agents/extensions/.\n - Boundary markers: Absent. No instructions are provided to the agent to isolate or ignore potential instructions embedded within these external files.\n
- Capability inventory: The skill utilizes the
tool_searchandmulti_agent_v1.spawn_agenttools to dynamically discover and execute subagents based on the data read from the local files.\n - Sanitization: Absent. There is no evidence of validation or filtering of the content read from these local paths before it influences the agent's behavior.
Audit Metadata