stream-builder

Warn

Audited by Socket on Sep 17, 2026

3 alerts found:

Securityx2Anomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core scaffolding behavior matches the stated purpose, but the skill's footprint is broadened by transitive skill installation, auto-install of a missing peer skill without confirmation, and several unpinned remote execution paths. No clear credential exfiltration or malicious data routing is shown, but trust expansion is disproportionate enough to rate it suspicious rather than benign.

Confidence: 87%Severity: 74%
SecurityMEDIUM
references/CROSS-PRODUCT.md

The code appears to implement legitimate Stream token provisioning rather than malware. However, as shown, the endpoint is high risk because it mints tokens and upserts users based solely on an unauthenticated query parameter, enabling likely user impersonation and unauthorized account creation or modification. The route should derive the identity from an authenticated session and verify authorization before provisioning tokens. No clear malicious payload or obfuscation is present.

Confidence: 97%Severity: 82%
AnomalyLOW
references/CHAT.md

The fragment is benign integration documentation with no evidence of malicious behavior or intentional obfuscation. The documented token endpoint is a security concern if implemented without authentication and authorization because the caller controls `user_id` and may obtain a token for another user. The endpoint should derive the user identity from an authenticated session, validate permissions, and never expose the API secret.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 17, 2026, 04:38 PM
Package URL
pkg:socket/skills-sh/getstream%2Fagent-skills%2Fstream-builder%2F@78a10857fec82ac9756bea6593763055f292ca9fb6e93073267e05e3b19e8941
Security Audit — socket — stream-builder