localize-figs-j

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing expo-localization and i18n-js via the npx package manager. These are well-known, standard libraries for localization in the React Native and Expo ecosystems.
  • [PROMPT_INJECTION]: The skill documents a potential surface for indirect prompt injection by advising the user to analyze external sources. 1. Ingestion points: web pages, app reviews, and competitor claims in references/04-discovery-listing.md. 2. Boundary markers: present; the skill explicitly warns to treat these as untrusted inputs until corroborated. 3. Capability inventory: limited; the skill provides guidance and code templates without invoking dangerous tools. 4. Sanitization: absent; the skill relies on manual user corroboration.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 11:18 PM
Security Audit — agent-trust-hub — localize-figs-j