color-contrast-auditor

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill features a surface for indirect prompt injection as it ingests and processes untrusted data from screenshots and codebase files.
  • Ingestion points: Visual analysis of screenshots and extraction of color definitions from style sheets and component files (SKILL.md).
  • Boundary markers: The skill does not define specific markers or instructions to isolate data from commands during ingestion.
  • Capability inventory: The skill utilizes toolsets for file reading, writing, editing, and web fetching (SKILL.md frontmatter).
  • Sanitization: There is no evidence of content sanitization or validation for the data extracted from users' project files.
  • [COMMAND_EXECUTION]: The documentation includes instructions for executing shell commands to perform automated accessibility audits.
  • Evidence: Use of npx lighthouse and npx pa11y for scanning URLs (SKILL.md).
  • [EXTERNAL_DOWNLOADS]: The skill references and suggests the use of well-known external accessibility services and tools.
  • Evidence: Recommends WebAIM, Coolors, and Adobe Color tools for contrast validation (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 12:24 PM
Security Audit — agent-trust-hub — color-contrast-auditor