software-localisation
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides high-quality technical documentation and configuration templates. Maintenance scripts located in the
scripts/directory perform benign tasks like regex-based linting of example code and validating external documentation links. - [EXTERNAL_DOWNLOADS]: The
scripts/check_urls.pyscript validates the availability of external resources defined indata/sources.json. These resources target well-known and trusted organizations such as Cloudflare, Vercel, Unicode, and established translation platform vendors. The script only performs HTTP requests to verify reachability and does not execute remote content. - [COMMAND_EXECUTION]: Various documentation files provide standard CLI commands for environment setup, package installation, and translation synchronization (e.g.,
npm install,ng build,phrase push). These commands are relevant to the primary localization purpose and involve reputable package registries and service providers. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external translation catalogs, which creates an indirect prompt injection surface. The documentation addresses this risk (e.g., XSS vulnerabilities in translation pipelines) in
references/icu-message-format.md, and provides recommendations for sanitization and secure coding practices.
Audit Metadata