ios-localization
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends the use of
xcstrings-tool, a third-party Swift Package Plugin hosted atgithub.com/liamnichols/xcstrings-tool. This repository is owned by an individual developer and is not affiliated with a recognized trusted organization, posing a potential supply chain risk if the tool is used to process project resources. - [EXTERNAL_DOWNLOADS]: The skill links to documentation on
sosumi.ai(e.g.,https://sosumi.ai/documentation/foundation/automatic-grammar-agreement) instead of official Apple developer documentation. Using non-official documentation proxies can expose users to outdated or maliciously modified information. - [COMMAND_EXECUTION]: The documentation provides several shell-based workflows that interact with the local environment:
- Build Tooling: Recommends executing
xcodebuild -exportLocalizationsandxcodebuild -importLocalizationsfor localization management. - Python Scripting: Includes a Python one-liner in
references/string-catalogs.mdintended to be run viapython3 -cto validate translation completion by parsing theLocalizable.xcstringsfile. - [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow for processing
Localizable.xcstrings(JSON format) files using external scripts and system tools. - Ingestion points: The provided Python script and
xcodebuildutility ingest content from external String Catalog files. - Boundary markers: There are no instructions or delimiters provided to protect the agent or system from malicious content that might be embedded in the localization keys or values of the JSON files.
- Capability inventory: The skill utilizes shell commands and Python execution to handle these data files.
- Sanitization: No validation or sanitization steps are recommended for the ingested String Catalog content.
Audit Metadata