Back to skill

Security audit

Localization Readiness Audit

Security checks for vulnerabilities and agentic risk

Overview

This skill is a read-only localization readiness audit guide with clear boundaries against modifying files, exposing customer data, selecting vendors, or making legal decisions.

Install this if you want a structured, draft localization-readiness audit. Be prepared to share product architecture, locale plans, and non-sensitive evidence such as file paths or config keys; avoid providing customer data, secrets, full unreleased strings, or relying on its legal flags as legal advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Unbounded Output

Medium
Category
Output Handling
Confidence
60% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
- Pseudolocalization enabled in CI for at least one build that exercises the full UI
- Expansion budget known (rule of thumb: short strings can grow 100–300%, German typically 30%, Russian 30–50%, Japanese can compress to 60%)
- No fixed-width / fixed-height containers around translated text without overflow handling
- No truncation that hides essential meaning (especially for verbs, prices, error messages)
- Text-baseline alignment respects taller scripts (Devanagari, Thai, Arabic) — line-height not pinned to Latin x-height
- Font stack covers target scripts (CJK, Arabic, Cyrillic, Devanagari, Thai, …) and fallbacks tested
- Variable fonts / web-font subsets serve the right script

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description says to use this skill whenever a product manager, engineering lead, or localization PM needs to audit a product surface for localization readiness, but it does not define concrete invocation phrases, boundaries, or exclusion examples. In a markdown skill description, this broad natural-language trigger could overlap with many general requests about localization planning or launch readiness.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.