seo-a11y-analyzer

Pass

Audited by Gen Agent Trust Hub on Jun 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the axe-core command-line interface through a provided shell script (scripts/validate-with-axe.sh) to automate accessibility audits of local files or remote URLs.
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to fetch the @axe-core/cli package from the official npm registry at runtime. This utilizes a well-known service for its intended diagnostic purpose.
  • [PROMPT_INJECTION]: The skill processes untrusted user-provided HTML and JavaScript files, which presents an indirect prompt injection surface where instructions hidden in comments or attributes could potentially influence agent behavior during analysis.
  • Ingestion points: HTML/JSX/TSX files read by the agent as specified in Step 1 of SKILL.md.
  • Boundary markers: None identified in the provided instructions to isolate analyzed content.
  • Capability inventory: Shell command execution via the axe-core CLI tool.
  • Sanitization: No specific content sanitization or escaping is described before the agent processes the file content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 29, 2026, 02:32 AM
Security Audit — agent-trust-hub — seo-a11y-analyzer