qa-testing-accessibility

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions and documentation recommend installing various well-known Node.js packages for accessibility testing, including @playwright/test, @axe-core/playwright, tsx, pa11y, @lhci/cli, and eslint-plugin-jsx-a11y. It also involves downloading browser binaries through Playwright's installation process.\n- [COMMAND_EXECUTION]: The provided TypeScript utility scripts/generate-a11y-baseline.ts uses the Playwright framework to launch a headless browser and navigate to URLs provided via environment variables (BASE_URL, PATHS). It executes axe-core analysis within the browser context and writes the resulting audit data to tests/a11y-baseline.json.\n- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from external websites by scanning them for accessibility violations. Evidence Chain: 1. Ingestion points: scripts/generate-a11y-baseline.ts crawls external URLs; 2. Boundary markers: The script produces a structured JSON baseline snapshot; 3. Capability inventory: Includes Playwright browser automation and local filesystem writes (writeFileSync); 4. Sanitization: The script extracts specific audit properties (id, impact, description) rather than raw page content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — qa-testing-accessibility