localise

Pass

Audited by Gen Agent Trust Hub on May 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a vulnerability surface for indirect prompt injection.\n
  • Ingestion points: Untrusted data enters the agent context through user-provided 'English source' documents and 'Romanian draft' inputs (SKILL.md).\n
  • Boundary markers: There are no delimiters or specific instructions provided to the agent to treat input text strictly as data and ignore any potential commands embedded within it.\n
  • Capability inventory: The skill utilizes 'ane_package.reporting.word_export' for file generation and an Edit tool for document modification (SKILL.md).\n
  • Sanitization: The skill description lacks any mention of sanitization, filtering, or validation of the input content before it is used for translation, review, or file export.
Audit Metadata
Risk Level
SAFE
Analyzed
May 22, 2026, 10:13 PM
Security Audit — agent-trust-hub — localise