stream-builder

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses standard package management tools like npm and npx to scaffold Next.js projects and install SDKs. It also utilizes the vendor's own CLI (getstream) for environment configuration and backend setup.
  • [DATA_SECURITY]: The skill implements proactive secret protection by verifying that .env* files are included in the project's .gitignore before writing credentials to disk. It also specifies that sensitive keys should never be committed or read by the agent itself.
  • [EXTERNAL_DOWNLOADS]: The skill downloads project templates from Shadcn (Vercel) and optional utility skills from trusted organizations (vercel-labs and anthropics). For non-essential extensions, the skill explicitly pauses and requests user consent before execution.
  • [INDIRECT_PROMPT_INJECTION]: The AI Support Agent recipe describes a system for processing untrusted user input via webhooks. It mitigates risks by implementing HMAC verification of payloads and providing clear architectural guidance on grounding and bot-loop prevention. The attack surface is typical for AI applications and handled with appropriate safeguards.
  • [DYNAMIC_EXECUTION]: Minimal use of node -e is observed for local file system utility tasks, such as renaming JSON fields in package.json or checking for existing icon packages. These operations are benign and restricted to the local development environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:35 PM
Security Audit — agent-trust-hub — stream-builder