gettext-i18n

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill uses standard Elixir development tools and dependencies. It references the gettext package and mix gettext.* commands which are the official and expected workflow for internationalization in the Elixir ecosystem.
  • [INDIRECT_PROMPT_INJECTION]: The skill correctly identifies a potential attack surface where user-controlled input (locale parameters) enters the application context. It proactively mitigates this risk by providing code examples and rules that mandate validating locale input against a strict allowlist (@supported_locales) before use.
  • Ingestion points: User-controlled parameters (conn.params["locale"]) and session data processed in the SetLocale plug.
  • Boundary markers: N/A.
  • Capability inventory: The skill focus is limited to string translation and locale management; it does not request or demonstrate file system writes, network operations, or shell execution capabilities.
  • Sanitization: Proactively demonstrated via the validate/1 function which uses a whitelist guard (when locale in @supported_locales).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 12:25 AM
Security Audit — agent-trust-hub — gettext-i18n