Back to skill

Security audit

Web Accessibility (WCAG 2 AA))

Security checks across malware telemetry and agentic risk

Overview

This skill provides WCAG accessibility guidance and a local contrast-checking script, with no evidence of hidden data access or unsafe behavior.

This is appropriate to install if you want an agent to apply WCAG accessibility practices or run local color-contrast checks. Review the guidance for fit with your project’s language and accessibility process, and only wire the validator into CI/build steps when you choose to enforce those checks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Confidence
83% confidence
Finding
The checklist includes the literal guidance `<html lang="en">` followed by a brief alternative, which can be read as defaulting output to English. Because policy violations include forcing a specific language without user opt-in, this line is worth flagging even though it partially mitigates the issue by saying 'or the page's language'.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.