skills/maxgfr/ultra11y/review-a11y/Gen Agent Trust Hub

review-a11y

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local script scripts/ultra11y.mjs using node to perform accessibility audits and apply fixes. This script is bundled with the skill and interacts with the local file system to analyze staged files, diffs, and branches.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection because it instructs the agent to ingest and adjudicate findings within untrusted project files.
  • Ingestion points: The agent reads local project files and git diffs via the node scripts/ultra11y.mjs audit command output and by manually opening cited lines.
  • Boundary markers: There are no instructions for using delimiters or explicit 'ignore instructions' warnings when the agent inspects the source code of the components being audited.
  • Capability inventory: The skill possesses file-writing capabilities through the fix --write command and general shell execution capabilities via Node.js.
  • Sanitization: The skill does not mention sanitizing or escaping the contents of the audited files before the agent processes them to 'adjudicate the judgment'.
  • [EXTERNAL_DOWNLOADS]: The skill provides a fallback command npx -y ultra11y to run the engine if the bundled script is unavailable. This command downloads and executes the ultra11y package from the public npm registry without user confirmation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 06:03 AM
Security Audit — agent-trust-hub — review-a11y