stream-builder
Audited by Socket on Sep 17, 2026
3 alerts found:
Securityx2AnomalySUSPICIOUS: the core scaffolding behavior matches the stated purpose, but the skill's footprint is broadened by transitive skill installation, auto-install of a missing peer skill without confirmation, and several unpinned remote execution paths. No clear credential exfiltration or malicious data routing is shown, but trust expansion is disproportionate enough to rate it suspicious rather than benign.
The code appears to implement legitimate Stream token provisioning rather than malware. However, as shown, the endpoint is high risk because it mints tokens and upserts users based solely on an unauthenticated query parameter, enabling likely user impersonation and unauthorized account creation or modification. The route should derive the identity from an authenticated session and verify authorization before provisioning tokens. No clear malicious payload or obfuscation is present.
The fragment is benign integration documentation with no evidence of malicious behavior or intentional obfuscation. The documented token endpoint is a security concern if implemented without authentication and authorization because the caller controls `user_id` and may obtain a token for another user. The endpoint should derive the user identity from an authenticated session, validate permissions, and never expose the API secret.