localize-ro

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses natural instructional language to define a persona for Romanian translation. No markers of bypass, safety filter overrides, or instruction-ignore patterns were detected.
  • [DATA_EXFILTRATION]: No network operations (curl, wget, fetch), hardcoded secrets, or access to sensitive local file paths (e.g., .ssh, .env) are present. The skill operates entirely on provided source text.
  • [REMOTE_CODE_EXECUTION]: There are no package installations or remote script executions. The skill does not download external code.
  • [OBFUSCATION]: The skill references specific Unicode codepoints (U+0218, U+0219, U+021A, U+021B) to distinguish between correct Romanian comma-below diacritics and Turkish cedilla homoglyphs. This is a legitimate linguistic requirement and not an attempt at obfuscation. No hidden URLs or encoded payloads were found.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill does not use the shell execution syntax (!command) in its markdown content.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes untrusted input (source text to be translated), it lacks any functional capabilities (such as file writing, command execution, or network requests) that could be exploited via an indirect injection attack.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 12:28 PM
Security Audit — agent-trust-hub — localize-ro