stream-docs
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses read-only Bash commands (grep, ls, cat) to inspect project configuration files like package.json, go.mod, and requirements.txt. These probes are limited to identifying the SDK version and framework used in the current directory.
- [EXTERNAL_DOWNLOADS]: The skill performs network requests to getstream.io using WebFetch to retrieve documentation and the llms.txt index. This is restricted to the official vendor domain and is consistent with the skill's purpose.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests documentation content from an external vendor source (getstream.io) to provide answers. The vulnerability is mitigated by the lack of dangerous capabilities (no file writing or arbitrary code execution) and instructions to provide verbatim quotes and citations.
Audit Metadata