a11y-audit
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute specific local scripts using Node.js and Python. These include 'scripts/measure_render.mjs' for layout measurement, 'scripts/verify_states.mjs' for interactive state auditing, and 'scripts/contrast.py' for color calculations. These scripts are invoked with user-provided files as arguments to facilitate the auditing process.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external UI or design files. This represents an attack surface where malicious content within the analyzed files could potentially influence agent behavior. However, the skill implements a structured verification protocol and specifically defined output requirements (WCAG finding tables), which serve as functional boundaries.
Audit Metadata