wenqu-translate

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill suggests manual user-initiated installation of related skills like baoyu-translate and wenqu-review to handle specific tasks. These commands are provided as documentation for the user and are not executed automatically.
  • [PROMPT_INJECTION]: The skill handles untrusted external content (READMEs, papers) which acts as an indirect prompt injection surface. Evidence: 1. Ingestion points: User-supplied text and local project preferences.md files. 2. Boundary markers: The translation-guide.md prescribes a pre-translation analysis phase to identify domain and tone. 3. Capability inventory: The skill can read local skill files and write to project-specific preference directories. 4. Sanitization: Explicit content sanitization is not mentioned, but the methodology focuses on re-writing rather than direct execution.
  • [DATA_EXFILTRATION]: The skill reads configuration guidelines from standard local skill paths (~/.agents/skills/wenqu-review/) and saves translation preferences to project-local directories to ensure context-aware results.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 05:06 AM
Security Audit — agent-trust-hub — wenqu-translate