i18n-rtl-l10n
Fail
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: HIGHOBFUSCATIONPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [OBFUSCATION]: The script
scripts/check_i18n_bans.shcontains hidden Unicode characters (likely from the U+E0000 Tag range) that encode steganographic content. These characters are non-rendering and typically used to bypass string-based security filters. - Evidence: Verification of steganographic Unicode sequences in
scripts/check_i18n_bans.shspecifically within the pattern definition for legacy bidi embeddings. - [PROMPT_INJECTION]: The hidden Unicode characters detected in
scripts/check_i18n_bans.share used to embed a steganographic prompt injection. This is an attempt to influence the behavior of the AI agent by providing instructions that are not visible to human reviewers but are interpreted by the model during processing. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its processing of user-controlled files without adequate protection.
- Ingestion points: The skill reads
app_*.arblocalization files and.dartsource code files using provided scripts. - Boundary markers: Absent. The skill does not use delimiters or explicit 'ignore' instructions when processing external content.
- Capability inventory: The provided scripts (
check_arb_parity.sh,check_i18n_bans.sh) utilize shell commands (bash,jq,grep,sed) to extract and process data from files. The AI agent is expected to execute these checks on the codebase. - Sanitization: Absent. The content of the strings being localized or analyzed is not sanitized before being processed by the scripts or read by the agent.
- [COMMAND_EXECUTION]: The skill provides bash scripts that execute tools like
jqandgrepon local files. While intended for validation, these scripts lack robust input sanitization, potentially allowing for command injection if malicious file names or contents are introduced into the project workspace.
Recommendations
- AI detected serious security threats
Audit Metadata