qa-testing-accessibility
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions and documentation recommend installing various well-known Node.js packages for accessibility testing, including @playwright/test, @axe-core/playwright, tsx, pa11y, @lhci/cli, and eslint-plugin-jsx-a11y. It also involves downloading browser binaries through Playwright's installation process.\n- [COMMAND_EXECUTION]: The provided TypeScript utility scripts/generate-a11y-baseline.ts uses the Playwright framework to launch a headless browser and navigate to URLs provided via environment variables (BASE_URL, PATHS). It executes axe-core analysis within the browser context and writes the resulting audit data to tests/a11y-baseline.json.\n- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from external websites by scanning them for accessibility violations. Evidence Chain: 1. Ingestion points: scripts/generate-a11y-baseline.ts crawls external URLs; 2. Boundary markers: The script produces a structured JSON baseline snapshot; 3. Capability inventory: Includes Playwright browser automation and local filesystem writes (writeFileSync); 4. Sanitization: The script extracts specific audit properties (id, impact, description) rather than raw page content.
Audit Metadata