accessibility-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and modify user-supplied interface code, creating a surface for potential injection attacks through untrusted data.
- Ingestion points: Project source files (HTML, CSS, JavaScript) accessed through
Read,Edit,Grep, andGlobtools. - Boundary markers: The instructions lack specific delimiting instructions or warnings to ignore commands potentially embedded within analyzed code comments or text.
- Capability inventory: The skill possesses the ability to write and edit files and execute shell commands via
npm,npx, andnodetools. - Sanitization: No input sanitization or filtering logic is present to validate the safety of the ingested content.
- [EXTERNAL_DOWNLOADS]: The skill facilitates the use of standard web auditing tools for its primary purpose.
- Evidence: Usage of
npx @axe-core/cliandnpx lighthousefor accessibility testing. - Source: These tools are sourced from the official NPM registry, a well-known and trusted service provider.
Audit Metadata