asc-localize-metadata

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external App Store metadata which acts as an indirect prompt injection surface. Ingestion points: Metadata downloaded via 'asc localizations download' in SKILL.md. Boundary markers: The translation prompt uses triple quotes as delimiters for untrusted content. Capability inventory: Writing to App Store Connect via 'asc localizations upload' and 'asc app-info set'. Sanitization: No explicit sanitization of metadata content is performed prior to translation.
  • [COMMAND_EXECUTION]: Executes 'asc' CLI commands for legitimate App Store management tasks. Commands are well-structured with explicit flags and deterministic ID selection to prevent accidental errors.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 09:39 AM