i18n-localization
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOWPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [Indirect Prompt Injection] (LOW): The skill is designed to analyze external project files via
Read,Glob, andGreptools. This creates an ingestion surface for untrusted data. If a project file contains malicious instructions within strings or comments, it could potentially influence the agent's reasoning. However, the lack ofWriteorShellcapabilities in theallowed-toolsmetadata limits the impact of such an attack. - [Metadata Poisoning] (LOW): There is a minor discrepancy between the metadata and the content. The
allowed-toolsfield specifiesRead,Glob, andGrep, but theScriptsection suggests executingpython scripts/i18n_checker.py. This inconsistency could lead to confusion regarding the skill's operational boundaries. - [Unverifiable Dependencies] (LOW): The skill references a local file
scripts/i18n_checker.pywhich was not included in the provided context for analysis. While local script references are common, the behavior of this script cannot be verified.
Audit Metadata