deepl
Warn
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell scripts to interact with the DeepL API and process files. These scripts interpolate user-provided variables like
{{user_text}}and{{user_path}}directly into shell commands. While some quoting is used, this pattern is susceptible to command injection if the input contains shell metacharacters or sequences designed to break out of the variable context. - [DATA_EXFILTRATION]: The skill allows the agent to read and upload local files to an external API (DeepL). A malicious prompt could trick the agent into providing paths to sensitive system files (e.g.,
.env, SSH keys, or configuration files), leading to the exfiltration of private data to the DeepL service. - [PROMPT_INJECTION]: The skill processes untrusted external data (texts and file contents). It is vulnerable to indirect prompt injection where malicious instructions embedded in the source text or files could be interpreted and executed by the agent after translation, potentially bypassing safety guardrails.
- [CREDENTIALS_UNSAFE]: The skill requires a
DEEPL_API_KEYand instructs users to set it as an environment variable. While not hardcoded, environment variables can sometimes be exposed through process listings or logs in shared execution environments.
Audit Metadata