accesslint-audit
Pass
Audited by Gen Agent Trust Hub on Jun 12, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface (Category 8) because it ingests untrusted data from web URLs and HTML files while maintaining the capability to modify local source code.\n- Ingestion points: Untrusted data enters the agent context through the
audit_live(URLs) andaudit_html(local files or strings) tools mentioned in SKILL.md.\n- Boundary markers: Absent; there are no instructions for the agent to use delimiters or ignore potential commands embedded within the audited HTML content.\n- Capability inventory: The skill can read and write to the local filesystem and perform browser automation/interaction.\n- Sanitization: Absent; the instructions encourage the agent to treat findings and fix directives as authoritative without additional validation or sanitization steps.
Audit Metadata