frontend-internationalization-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard implementation patterns for internationalization.\n- [INDIRECT_PROMPT_INJECTION]: The skill includes a pattern for serving locale resources via an API route (rules/locales-resource-route.md) which ingests user-controlled parameters (lng and ns).\n
- Ingestion points: The loader function in rules/locales-resource-route.md reads from params.lng and params.ns.\n
- Boundary markers: None.\n
- Capability inventory: Serving JSON data via the data utility from react-router.\n
- Sanitization: The skill implements strict validation using Zod enum checks against the keys of the internal resources object, which effectively prevents path traversal or access to unintended data.\n- [DATA_EXPOSURE]: The skill defines a localeCookie with httpOnly: true and secure: process.env.NODE_ENV === "production" in rules/setup-middleware.md, which aligns with security best practices for preventing client-side script access to sensitive cookies.
Audit Metadata