localize-es

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, untrusted source text for localization and translation tasks. This creates an attack surface for indirect prompt injection where adversarial instructions could be embedded in the source strings.
  • Ingestion points: Processes UI strings, marketing copy, and documentation as specified in SKILL.md.
  • Boundary markers: The skill does not define specific delimiters or instructions to isolate user-provided text from the agent's instructions.
  • Capability inventory: The skill contains no file-writing, network, or command execution capabilities; it is limited to text generation.
  • Sanitization: There is no evidence of input validation or sanitization rules for the processed text.
  • [SAFE]: The skill follow best practices for localization and does not request excessive permissions or include any known malicious patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 07:51 AM
Security Audit — agent-trust-hub — localize-es