turkish-humanizer

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-provided text for naturalization, creating a surface for indirect prompt injection. \n
  • Ingestion points: User-supplied passages, UI copy, and articles provided for humanization (SKILL.md). \n
  • Boundary markers: The skill instructs the agent to wrap output in <metin> tags, though input boundaries are not strictly defined. \n
  • Capability inventory: The skill possesses no external capabilities; it lacks access to network tools, filesystem operations, or shell execution. \n
  • Sanitization: There is no explicit sanitization of input text, though the lack of capabilities mitigates the risk.
  • [SAFE]: The skill includes code snippets in references/mechanics.md to demonstrate correct Turkish locale handling in various programming languages (JS, Python, Java, C#). These are educational examples intended to prevent software bugs (e.g., the Turkish I problem) and are not executable within the agent's context.
  • [SAFE]: All external references and methodologies cited (such as TDK, Nurullah Ataç, Vinay & Darbelnet) are well-known linguistic and translation resources, contributing solely to the naturalization logic without security implications.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:30 PM
Security Audit — agent-trust-hub — turkish-humanizer