accessibility-auditing
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from external web pages via the
browser_navigateandbrowser_snapshottools inSKILL.md. This data could contain malicious instructions designed to mislead the agent. - Ingestion points: External web content retrieved from user-specified URLs.
- Boundary markers: The skill does not define specific delimiters to separate the retrieved page content from its internal logic.
- Capability inventory: The skill utilizes browser navigation, DOM/ARIA snapshots, and simulated keyboard events.
- Sanitization: There are no instructions for sanitizing or filtering the content of the accessibility tree before analysis.
Audit Metadata