accesslint-audit

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses browser automation tools (Chrome DevTools, Playwright, Puppeteer) to perform live DOM audits. It also performs file system read and write operations when in 'fix mode' to apply accessibility repairs to the codebase.
  • [DATA_EXPOSURE]: To perform its primary function, the skill accesses local source code files and interacts with external URLs (typically development servers or live production sites) for auditing.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data by ingesting HTML from web pages and reading source code. While this represents a potential attack surface for indirect instructions, the skill limits impact by requiring specific modes (Report vs. Fix) and advising human review for non-mechanical fixes.
  • Ingestion points: External URLs via audit_live and local files via Read and audit_html (SKILL.md).
  • Boundary markers: None explicitly defined for data interpolation.
  • Capability inventory: File read/write operations and network access via browser automation (SKILL.md).
  • Sanitization: None specified for ingested HTML content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 08:45 AM