stream-builder

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the main build/scaffold behavior aligns with the stated Stream app-builder purpose and uses mostly legitimate ecosystems, but the skill overreaches by auto-installing peer skills, optionally installing third-party skills from mutable GitHub branches, and pushing network/auth actions with minimal confirmation. This looks more like an aggressive automation skill than confirmed malware, but its transitive trust model and broad execution scope materially raise risk.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
May 7, 2026, 04:46 PM
Package URL
pkg:socket/skills-sh/GetStream%2Fagent-skills%2Fstream-builder%2F@d0c1b67f8b5271fa5d273cf0280b994ff9c2544a