human-translation

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation references the use of @402md/x402 and @402md/mcp. These are vendor-provided libraries for handling payments and integration within the 402md ecosystem.
  • [SAFE]: The skill interacts with its designated base URL at api.translatorsco.com to perform its primary function of human translation. User-provided text is sent to this endpoint as part of the intended service workflow.
  • [SAFE]: The skill ingests untrusted text via the /v1/jobs endpoint and returns translated results. While this constitutes an attack surface for indirect prompt injection, the skill lacks any executable capabilities—such as file system access or subprocess execution—that could be exploited by malicious content within the processed data.
  • [SAFE]: Mandatory Evidence Chain for Indirect Prompt Injection: 1. Ingestion points: SKILL.md (via inputSchema in the /v1/jobs endpoint). 2. Boundary markers: Absent. 3. Capability inventory: No local subprocesses, file writes, or command execution capabilities detected. 4. Sanitization: No specific sanitization or filtering of the input or output text is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 12:46 PM
Security Audit — agent-trust-hub — human-translation