Back to skill

Security audit

xdoc-translation

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Xdoc translation helper that sends user-selected text or documents to Xdoc and does not include hidden code, installers, or automatic execution.

Install only if you are comfortable sending selected documents or text to Xdoc for translation. Use a revocable API key, avoid confidential or regulated material unless Xdoc's terms meet your requirements, and review before creating, editing, or deleting glossary and translation-memory resources.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The manifest advertises document and text translation features but does not clearly warn users, near the feature description, that submitted content is sent to an external Xdoc service and retained for 7 days. Because this skill handles potentially sensitive documents and text, the omission can mislead users into sharing confidential data without informed consent, increasing privacy and compliance risk.

Static analysis

No suspicious patterns detected.