a11y-audit

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute specific local scripts using Node.js and Python. These include 'scripts/measure_render.mjs' for layout measurement, 'scripts/verify_states.mjs' for interactive state auditing, and 'scripts/contrast.py' for color calculations. These scripts are invoked with user-provided files as arguments to facilitate the auditing process.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external UI or design files. This represents an attack surface where malicious content within the analyzed files could potentially influence agent behavior. However, the skill implements a structured verification protocol and specifically defined output requirements (WCAG finding tables), which serve as functional boundaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 10:24 AM
Security Audit — agent-trust-hub — a11y-audit