ToolProof Trust Profile

ai-i18nagent-i18n-agent

Do not install from this profile alone. High-impact signals or incomplete controls/evidence require manual review.

100risk score
Review Firstconnection signal
destructive_capabilityrisk type
86evidence score
Source: https://github.com/i18n-agent/mcp-client
Registry: ai.i18nagent/i18n-agent 1.16.3

Connection signal

Do not install from this profile alone. High-impact signals or incomplete controls/evidence require manual review.

Observed tools

  • None observed in this static profile.

Top findings

  • Detected capability: shell_execution — i18n-agent.js:202
  • Broad or write-capable OAuth/API scope: github_write_scope — .claude-plugin/marketplace.json:18
  • Detected capability: environment_access — i18n-agent.js:48

Recommended controls

  • Install in a sandbox before team or production use.
  • Pin the exact package/repository version.
  • Review install scripts, Dockerfile behavior, and dependency pins.
  • Do not use production credentials during first install.
  • Restrict filesystem, repository, cloud, and database scope.
  • Require human approval for destructive actions.