polystella-consumer
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection Surface: The skill is designed to process content collections—such as Markdown, MDX, and YAML files—and pass them to AI providers (Workers AI or Anthropic) for translation. Ingesting and processing external or untrusted data through large language models (LLMs) presents a potential surface for indirect prompt injection, where malicious instructions embedded in the source content could influence the translation process. The skill incorporates several mitigation strategies, including Zod-based schema validation, glossary enforcement, and drift detection to maintain consistency and safety.
- Sensitive Data Handling: The configuration examples demonstrate the use of environment variables for managing Cloudflare R2 credentials and API tokens. The skill explicitly advises against committing these secrets to version control and recommends using a
.envfile, which follows industry-standard security practices for secret management. - External Resource Integration: The skill references external packages and documentation hosted on GitHub. These references are essential for the integration of the localization library and point to the official resources provided by the developer.
Audit Metadata