review-a11y
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local script
scripts/ultra11y.mjsusingnodeto perform accessibility audits and apply fixes. This script is bundled with the skill and interacts with the local file system to analyze staged files, diffs, and branches. - [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection because it instructs the agent to ingest and adjudicate findings within untrusted project files.
- Ingestion points: The agent reads local project files and git diffs via the
node scripts/ultra11y.mjs auditcommand output and by manually opening cited lines. - Boundary markers: There are no instructions for using delimiters or explicit 'ignore instructions' warnings when the agent inspects the source code of the components being audited.
- Capability inventory: The skill possesses file-writing capabilities through the
fix --writecommand and general shell execution capabilities via Node.js. - Sanitization: The skill does not mention sanitizing or escaping the contents of the audited files before the agent processes them to 'adjudicate the judgment'.
- [EXTERNAL_DOWNLOADS]: The skill provides a fallback command
npx -y ultra11yto run the engine if the bundled script is unavailable. This command downloads and executes theultra11ypackage from the public npm registry without user confirmation.
Audit Metadata