web-issue-fixer
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill acts on external data in the form of accessibility issue descriptions. While this represents a potential attack surface for malicious instructions, the skill mitigates this risk by requiring mandatory user confirmation for every code change and providing clear before/after diffs.
- [DYNAMIC_EXECUTION]: The skill generates code patches (HTML, React, Vue, etc.) dynamically based on the detected framework and specific accessibility failures. These patches are applied to the source code using standard editing tools only after being presented to the user for review.
- [SAFE]: All external documentation links refer to trusted organizations, including the W3C (w3.org) and the WHATWG (whatwg.org). The suggested Playwright verification dependency is a well-known industry standard tool for accessibility testing.
Audit Metadata