how-to-crowdin
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and analyze information from external vendor websites (
store.crowdin.comandsupport.crowdin.com) to suggest solutions. This creates a surface where content on those external pages could theoretically be used to influence or manipulate the agent's behavior. \n - Ingestion points: The skill fetches
llms.txtindexes and individual description files from Crowdin's official store and documentation domains as directed inreferences/catalogs.md.\n - Boundary markers: The instructions do not define specific delimiters or instructions for the agent to treat the fetched remote content as untrusted or to ignore embedded commands.\n
- Capability inventory: Although the skill itself is a triage layer, it has the capability to delegate tasks to powerful skills such as
crowdin-cli,crowdin-api-client, andcreate-app.\n - Sanitization: The skill does not perform any validation, filtering, or sanitization of the remote text content before processing it. \n- [EXTERNAL_DOWNLOADS]: The skill fetches catalog data and help documentation from vendor-owned domains (
store.crowdin.comandsupport.crowdin.com). These network operations are legitimate lookups used to provide accurate and up-to-date recommendations based on current platform features and available marketplace apps.
Audit Metadata