ibm-a11y-route-scan

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local script scripts/a11y/a11y_scan.py via the uv tool to perform accessibility evaluations. This is the primary intended function of the skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes JSON files (routes and state definitions) to control scanning behavior. These files define UI interactions like clicking and typing. While this is an input surface, it is used for local developer tooling.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 08:32 AM
Security Audit — agent-trust-hub — ibm-a11y-route-scan