localization-strategy

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk localization planning skill with no executable code, though it may use local project context files to tailor its advice.

Review any `.claude/project-context.md` or `.cursor/project-context.md` files before using this skill, since it may read them for product and market context. Otherwise, the skill is proportionate for localization strategy and does not install code or request sensitive access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The skill's activation text is quite broad, including generic terms like 'global expansion,' 'market entry,' and 'international SEO,' which can cause the agent to invoke this skill in situations that are only loosely related to localization strategy. Over-broad routing is a real security and safety concern because it increases the chance of inappropriate context capture, wrong tool selection, and higher-priority skills being bypassed or diluted.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal