dify-docs-terminology-check

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes various shell commands including git fetch, git rev-parse, grep, and git grep. These commands are used to interact with the local documentation repository and a user-specified Dify codebase to verify terminology consistency and resolve commit references.
  • [DYNAMIC_EXECUTION]: The skill invokes project-specific Python scripts, specifically tools/translate/check-glossary-keys.py and tools/translate/derive-termbase.py. These scripts are used to validate glossary keys against the codebase and regenerate termbases after approved edits.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from documentation files and external codebase files, creating a potential surface for indirect prompt injection.
  • Ingestion points: The skill reads content from markdown files (.md, .mdx), glossary.md, and internationalization JSON files in the Dify repository.
  • Boundary markers: Not explicitly defined; the skill parses and extracts bolded terms and headings for comparison.
  • Capability inventory: The skill has the ability to execute shell commands (grep, git), run local Python scripts, and perform file writes to glossary.md upon user approval.
  • Sanitization: No explicit sanitization or validation of the content extracted from the files is performed before it is used in search queries or displayed in reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 01:03 PM