llm-streaming-response-handler

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references several well-known and trusted Node.js packages for LLM integration and cost estimation, such as ai, @ai-sdk/openai, and @ai-sdk/anthropic from Vercel, and tiktoken from OpenAI.\n- [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for processing real-time data from external LLM APIs, which inherently involves an indirect prompt injection surface as the agent processes potentially untrusted content.\n
  • Ingestion points: Data is received via the fetch API stream reader in the provided code examples and the stream_tester.ts utility.\n
  • Boundary markers: The provided code snippets demonstrate standard streaming handling without explicit delimiter-based isolation of the untrusted model output.\n
  • Capability inventory: The skill is focused on UI display and utility scripts; it does not grant capabilities for executing the streamed content as code or shell commands.\n
  • Sanitization: Content sanitization is not explicitly implemented in the provided boilerplate patterns, leaving this responsibility to the developer using the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:13 AM
Security Audit — agent-trust-hub — llm-streaming-response-handler