lokalise-security-basics

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides security best practices and auditing tools for Lokalise integrations, including scoped token management and webhook verification.
  • [CREDENTIALS_SAFE]: The skill correctly uses environment variables and CI/CD secrets for API token handling. It includes a dedicated script for auditing codebases to detect and prevent the accidental inclusion of hardcoded tokens in source files or Git history.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted translation data (e.g., JSON locale files). It implements proactive security measures by providing validation logic that scans for XSS patterns, credential leaks, and malformed placeholders within the translation strings.
  • [COMMAND_EXECUTION]: The skill uses standard command-line tools like grep and the official lokalise2 CLI for auditing and synchronization tasks in a non-malicious manner.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:47 AM
Security Audit — agent-trust-hub — lokalise-security-basics