airflow-translations
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute project-specific development tools including
breezeand a tool namedprek(likely a typo for the standardpre-commitframework). These commands are used for checking translation completeness and running validation hooks. breeze ui check-translation-completeness --language <locale>prek run --from-ref main --hook-stage pre-commit- [INDIRECT_PROMPT_INJECTION]: The skill processes external data in the form of translation strings stored in JSON files, creating an indirect prompt injection surface.
- Ingestion points: Translation JSON files located in
airflow-core/src/airflow/ui/public/i18n/locales/. - Boundary markers: The instructions explicitly warn not to translate or remove variable names inside
{{…}}delimiters, which helps preserve the integrity of the interpolation logic. - Capability inventory: The skill uses
breezeandpre-commithooks to validate and format files, but does not perform dangerous operations like arbitrary code execution or network exfiltration based on the ingested content. - Sanitization: The skill relies on pre-commit hooks and the
breezetool's completeness check to validate the structure and content of the translation files.
Audit Metadata