Back to skill

Security audit

Cuihua i18n Helper

Security checks for vulnerabilities and agentic risk

Overview

The skill is related to i18n work, but its documentation overstates AI translation features and under-discloses file changes and possible third-party translation data sharing.

Review this before installing. Use it only with a clean working tree and explicit source/locales paths, expect it to read project UI code and write locale JSON files, and do not allow cloud translation of sensitive project strings unless you have approved the provider and data handling terms.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code is genuinely related to internationalization, so the overall domain matches the description. However, key advertised capabilities are not implemented. There is no AI integration, no API calls, no translation engine, no batch translation workflow, and no support shown for 100+ languages beyond accepting a configurable list. The implementation mainly performs local file scanning, string extraction, locale file generation, and basic coverage checks. This is a material overstatement of functionality, so the description does not accurately represent the actual behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation states that locale files are auto-created but does not clearly warn users that running the tool will create and modify files in the locales directory. In an automated agent setting, this can lead to unexpected workspace changes, accidental overwrites, or propagation of machine-generated translations without informed user consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README includes very generic agent prompt examples such as extracting strings or translating files, which can overlap with ordinary user requests and cause the skill to activate unintentionally. In an agent environment, this increases the chance of unreviewed file reads and modifications to source and locale files when the user did not explicitly intend to invoke this specific skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises batch translation to 100+ languages but omits a clear warning that project strings may be sent to third-party providers. That omission is dangerous because codebase strings often contain internal terminology, feature names, operational details, secrets accidentally hardcoded in UI text, or regulated content, and users may not realize they are disclosing data externally.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The invocation phrase 'Translate to Chinese, Japanese, and Spanish' is broad and can match ordinary user conversation rather than an explicit request to operate on repository files. In an agent environment, ambiguous triggers can cause unintended processing of project content and accidental submission of strings to external translation services without clear confirmation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The example 'Check for missing translations' is also broadly phrased and may trigger routine scans across a codebase without the user specifying scope, files, or intended side effects. In agentic tooling, loose activation patterns increase the chance of unintended repository analysis, file modifications, or follow-on translation actions that the user did not explicitly authorize.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The Privacy & Security section says processing is local and that translations are not retained on servers, yet the same document instructs users to send strings to external providers such as DeepL, Google Translate, Azure, and OpenAI via API keys. This can cause developers to unknowingly transmit potentially sensitive source strings, UI text, or embedded business data to third parties under false privacy assumptions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code sets default target languages to ['zh', 'ja'], which imposes specific locales by default rather than offering a user-selected language or locale choice. This is reinforced again in the CLI defaults, making the skill behavior locale-constraining without visible opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI instantiates the helper with targetLanguages fixed to ['zh', 'ja'], which means users invoking the tool receive those locales regardless of preference unless they modify code. This is a natural-language locale policy issue because the skill behavior enforces particular languages rather than presenting a choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file is named as a Japanese locale resource (ja.json), but all user-facing strings are in English. That creates a language/locale policy issue because users selecting or receiving the Japanese locale would be served English without any opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON file is under a Chinese locale path (locales/zh.json) but the user-facing strings are written in English. That can indicate the skill forces or serves the wrong language for users expecting Chinese, which is a natural-language locale policy concern when no opt-in or justification is present.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.