translate
Warn
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
uv run pythonandnodeto execute numerous local scripts that manage project progress, terminology, and translation drafts. This includes scripts such asscripts/progress_edit.py,scripts/translation_context.py, andscripts/draft.py.- [DYNAMIC_EXECUTION]: In thecodex-tier.mdfile, the skill instructs the agent to dynamically resolve a script path and execute it:node "$(find ~/.claude/plugins/cache/openai-codex -maxdepth 4 -name codex-companion.mjs | head -1)". Resolving and executing code from paths computed at runtime is a risk as it can be redirected in compromised environments.- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted Markdown chapters and interpolates them into LLM prompts, creating a surface for indirect prompt injection.\n - Ingestion points: Raw chapter content is loaded into the
<SOURCE_CONTENT>placeholder withintranslator-prompt.mdandsemantic-reviewer-prompt.md.\n - Boundary markers: The prompts use standard Markdown fences but lack unique delimiters or explicit instructions to the agent to ignore instructions embedded in the source text.\n
- Capability inventory: The skill has the ability to write to the repository (
draft.py writeback), regenerate site navigation (generate_nav.py), and run a production build handoff (translation_completion.py).\n - Sanitization: No sanitization or filtering of the source Markdown content is mentioned before it is processed by the agent.
Audit Metadata