software-accessibility

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The script scripts/run_axe.sh utilizes npx to fetch and execute the @axe-core/cli package from the NPM registry. This is a standard developer workflow for accessibility testing and targets a well-known, industry-standard auditing library.
  • [COMMAND_EXECUTION]: The skill includes a bash script (scripts/run_axe.sh) intended to be executed in a shell environment to perform accessibility scans on target URLs. The script follows shell best practices such as set -euo pipefail and proper variable quoting to prevent simple command injection from arguments.
  • [INDIRECT_PROMPT_INJECTION]: As the skill is designed to ingest and remediate user-provided source code and external audit data (like JSON reports or HTML from audited URLs), it possesses an inherent surface for indirect prompt injection.
  • Ingestion points: User-provided code snippets in prompt context, audit reports processed by scripts/check_a11y_baseline.py, and target URL content processed by scripts/run_axe.sh.
  • Boundary markers: The instructions do not define specific delimiters for separating untrusted user code from the agent's instructions.
  • Capability inventory: Shell execution capabilities via scripts/run_axe.sh and file system read access via scripts/check_a11y_baseline.py.
  • Sanitization: The skill provides instructions for identifying risks in AI-generated code but does not include automated sanitization for external inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — software-accessibility