intlayer-usage

Pass

Audited by Gen Agent Trust Hub on Mar 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill package is composed entirely of Markdown documentation and license information. No executable scripts, binaries, or automated tasks are included in the skill.
  • [EXTERNAL_DOWNLOADS]: The documentation references multiple official Intlayer ecosystem packages and provides links to the official website and GitHub repository. All these resources (including the '@intlayer/mcp' server) are part of the legitimate infrastructure of the vendor 'aymericzip'.
  • [COMMAND_EXECUTION]: The skill documentation describes standard command-line interface usage, such as 'npx intlayer build' and 'npx intlayer auto-fill'. These commands are intended for use by developers within their local environments and are not executed by the skill itself.
  • [PROMPT_INJECTION]: An indirect prompt injection surface is identified because the documented framework processes user-defined content declarations and integrates with AI providers for automated translations. This is a functional aspect of the framework rather than a security defect in the skill. Evidence Chain: (1) Ingestion points: Local declaration files (*.content.ts) and distant CMS dictionaries. (2) Boundary markers: Not explicitly defined in the documentation. (3) Capability inventory: Generating dictionaries and types, and performing AI-assisted translations via CLI. (4) Sanitization: Described as being handled internally by the framework's core library.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 8, 2026, 05:28 PM