blog-localize
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted text content in the form of translated blog posts (Phase 1, Step 3). This data influences downstream operations such as web searches and statistics localization. While the skill includes proactive security measures, the ingestion of external data for complex reasoning constitutes a potential attack surface.
- Ingestion points: Reads translated post files from the project root (Phase 1, Step 3).
- Boundary markers: The instructions do not specify explicit delimiters or "ignore" instructions for the processed content when it is passed to the underlying agent tools.
- Capability inventory: Performs web searches (Phase 3a), fetches external URLs via network requests (Phase 3b), and writes files to the project directory (Phase 5).
- Sanitization: The skill incorporates significant security guardrails, including path traversal checks for file operations (resolving inside root, rejecting symlinks) and comprehensive SSRF validation for remote URL fetching (rejecting non-HTTPS, internal IPs, and specific protocols).
Audit Metadata