aigw-contrib-add-translator
Pass
Audited by Gen Agent Trust Hub on Apr 27, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill instructions define an interface for processing untrusted data from LLM providers, which constitutes a surface for Indirect Prompt Injection.
- Ingestion points: LLM request bodies and streaming response chunks (body []byte, chunk []byte) processed in SKILL.md.
- Boundary markers: The templates rely on structured JSON schema parsing rather than explicit boundary markers.
- Capability inventory: The provided logic is restricted to memory-based JSON transformations; no file system or network capabilities are included in the translator templates.
- Sanitization: The skill mandates the use of the gjson library for field extraction and validation, which is a safer alternative to manual string parsing.
- [REMOTE_CODE_EXECUTION]: The Go templates reference well-known third-party libraries (github.com/tidwall/gjson, github.com/tidwall/sjson, github.com/stretchr/testify) and project-internal modules from the envoyproxy organization for JSON handling and testing.
Audit Metadata