color-contrast-auditor
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill features a surface for indirect prompt injection as it ingests and processes untrusted data from screenshots and codebase files.
- Ingestion points: Visual analysis of screenshots and extraction of color definitions from style sheets and component files (SKILL.md).
- Boundary markers: The skill does not define specific markers or instructions to isolate data from commands during ingestion.
- Capability inventory: The skill utilizes toolsets for file reading, writing, editing, and web fetching (SKILL.md frontmatter).
- Sanitization: There is no evidence of content sanitization or validation for the data extracted from users' project files.
- [COMMAND_EXECUTION]: The documentation includes instructions for executing shell commands to perform automated accessibility audits.
- Evidence: Use of
npx lighthouseandnpx pa11yfor scanning URLs (SKILL.md). - [EXTERNAL_DOWNLOADS]: The skill references and suggests the use of well-known external accessibility services and tools.
- Evidence: Recommends WebAIM, Coolors, and Adobe Color tools for contrast validation (SKILL.md).
Audit Metadata