Back to skill

Security audit

Accessibility Check

Security checks for vulnerabilities and agentic risk

Overview

This is a plain accessibility review skill with no executable code, network behavior, credential handling, or hidden persistence observed.

Install this only if you want an agent to assist with frontend accessibility audits. Expect it to inspect relevant UI/code paths and possibly create a local report under reports/. Its trigger wording is broad, so users who only want explicit audit invocation may prefer tighter activation metadata, but no malicious or high-impact behavior was found.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

md
- ID: `fec-accessibility-check`
- Category: `review-quality`
- Version: `2.9.0`
- Source: `skills/fec-accessibility-check/SKILL.md`

## Description

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description says to use the skill when reviewing or improving a wide range of frontend accessibility topics, but it does not define specific trigger phrases, scope limits, or exclusion conditions. This broad natural-language activation guidance could overlap with many general frontend review requests and lead to unintended invocation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L03 says to use the skill when "reviewing or improving frontend accessibility" and lists broad terms like "accessibility" and "WCAG" as triggers. These phrases can occur in many ordinary frontend discussions, and the file does not provide exclusion conditions or negative examples to clarify when the skill should not activate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description includes very broad trigger terms such as 'accessibility', 'a11y', 'WCAG', and 'screen reader', causing the skill to activate for a wide range of frontend-review prompts. Overly broad activation in a manifest is a real quality/security concern because it can make the agent invoke this skill unnecessarily, increasing prompt-surface exposure and potentially displacing a more appropriate skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The package description says to use the skill when reviewing or improving a wide range of frontend concerns and includes generic trigger terms like "accessibility" without any limiting context or exclusion conditions. In a manifest file, this can create ambiguous activation scope and increase the chance of unintended invocation during ordinary accessibility-related discussion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

Line L03 explicitly defines "Chinese triggers" for activation, which imposes a language-specific behavior without stating that language selection is optional or user-controlled. This can violate language/locale policy expectations when no opt-in or broader language choice is documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The description explicitly states that Chinese triggers include certain terms, but it does not present this as an optional locale setting or explain a region-specific need. This introduces a language-specific policy choice in natural-language metadata without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.