fe-i18n
Audited by Socket on Feb 17, 2026
1 alert found:
Malware[Skill Scanner] Installation of third-party script detected All findings: [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] data_exfiltration: Credential file access detected (DE002) [AITech 8.2.3] [HIGH] data_exfiltration: Credential file access detected (DE002) [AITech 8.2.3] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] BENIGN: The skill is a coherent, proportional i18n integration guide and example code for next-intl in a Next.js app. It reads route params and local JSON message files, performs locale validation, and renders translations to clients. There are no suspicious network endpoints, credential access, dynamic code execution, or obfuscation. Standard implementation caveats (ensure message files are trusted and avoid injecting untrusted HTML) apply, but no supply-chain or exfiltration indicators are present.