web-quality-audit

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves its stated purpose as a web quality auditing tool. It provides comprehensive documentation on Lighthouse-based audit categories and a shell script for static analysis of HTML files.
  • [COMMAND_EXECUTION]: The skill includes a bash script scripts/analyze.sh which uses standard utilities like grep and find to analyze local HTML files. This behavior is expected for the skill's purpose and does not involve risky patterns like privilege escalation or exfiltration.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on user-provided HTML files and project code. While this is an ingestion point for external data, the current logic is based on static regex checks and documentation, posing no significant risk of indirect prompt injection that could influence agent behavior beyond the audit context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 12:23 AM
Security Audit — agent-trust-hub — web-quality-audit