review-a11y
Pass
Audited by Gen Agent Trust Hub on Jul 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purely instructional and contains no executable scripts, shell commands, or network operations. It guides the agent through an accessibility checklist for code review purposes.
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and analyze user-provided code diffs or file paths, which constitutes an attack surface for indirect prompt injection. However, the risk is minimal as the instructions explicitly state the agent must only report findings and is strictly forbidden from editing or refactoring code. No dangerous capabilities (like file writes or network access) are requested or used.
Audit Metadata