NYC
skills/smithery/ai/i18n-localization/Gen Agent Trust Hub

i18n-localization

Pass

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: LOWPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [Indirect Prompt Injection] (LOW): The skill is designed to analyze external project files via Read, Glob, and Grep tools. This creates an ingestion surface for untrusted data. If a project file contains malicious instructions within strings or comments, it could potentially influence the agent's reasoning. However, the lack of Write or Shell capabilities in the allowed-tools metadata limits the impact of such an attack.
  • [Metadata Poisoning] (LOW): There is a minor discrepancy between the metadata and the content. The allowed-tools field specifies Read, Glob, and Grep, but the Script section suggests executing python scripts/i18n_checker.py. This inconsistency could lead to confusion regarding the skill's operational boundaries.
  • [Unverifiable Dependencies] (LOW): The skill references a local file scripts/i18n_checker.py which was not included in the provided context for analysis. While local script references are common, the behavior of this script cannot be verified.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 16, 2026, 09:46 AM