gettext-i18n
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFE
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill uses standard Elixir development tools and dependencies. It references the
gettextpackage andmix gettext.*commands which are the official and expected workflow for internationalization in the Elixir ecosystem. - [INDIRECT_PROMPT_INJECTION]: The skill correctly identifies a potential attack surface where user-controlled input (locale parameters) enters the application context. It proactively mitigates this risk by providing code examples and rules that mandate validating locale input against a strict allowlist (@supported_locales) before use.
- Ingestion points: User-controlled parameters (
conn.params["locale"]) and session data processed in theSetLocaleplug. - Boundary markers: N/A.
- Capability inventory: The skill focus is limited to string translation and locale management; it does not request or demonstrate file system writes, network operations, or shell execution capabilities.
- Sanitization: Proactively demonstrated via the
validate/1function which uses a whitelist guard (when locale in @supported_locales).
Audit Metadata