asc-localize-metadata
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes external App Store metadata which acts as an indirect prompt injection surface. Ingestion points: Metadata downloaded via 'asc localizations download' in SKILL.md. Boundary markers: The translation prompt uses triple quotes as delimiters for untrusted content. Capability inventory: Writing to App Store Connect via 'asc localizations upload' and 'asc app-info set'. Sanitization: No explicit sanitization of metadata content is performed prior to translation.
- [COMMAND_EXECUTION]: Executes 'asc' CLI commands for legitimate App Store management tasks. Commands are well-structured with explicit flags and deterministic ID selection to prevent accidental errors.
Audit Metadata