stream-builder
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses standard package management tools like
npmandnpxto scaffold Next.js projects and install SDKs. It also utilizes the vendor's own CLI (getstream) for environment configuration and backend setup. - [DATA_SECURITY]: The skill implements proactive secret protection by verifying that
.env*files are included in the project's.gitignorebefore writing credentials to disk. It also specifies that sensitive keys should never be committed or read by the agent itself. - [EXTERNAL_DOWNLOADS]: The skill downloads project templates from Shadcn (Vercel) and optional utility skills from trusted organizations (
vercel-labsandanthropics). For non-essential extensions, the skill explicitly pauses and requests user consent before execution. - [INDIRECT_PROMPT_INJECTION]: The AI Support Agent recipe describes a system for processing untrusted user input via webhooks. It mitigates risks by implementing HMAC verification of payloads and providing clear architectural guidance on grounding and bot-loop prevention. The attack surface is typical for AI applications and handled with appropriate safeguards.
- [DYNAMIC_EXECUTION]: Minimal use of
node -eis observed for local file system utility tasks, such as renaming JSON fields inpackage.jsonor checking for existing icon packages. These operations are benign and restricted to the local development environment.
Audit Metadata