stream-react-native
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements strong security hygiene regarding credential management. It provides explicit rules and blueprints that guide developers to derive user identities server-side and use secure token providers instead of hardcoding secrets.
- [SAFE]: External downloads are strictly limited to the vendor's official domain (getstream.io) and GitHub (raw.githubusercontent.com) for the purpose of retrieving documentation and migration guides. These are treated as trusted sources.
- [SAFE]: Command execution is scoped to standard mobile development workflows (npm/yarn/npx, expo, pod install, xcrun). Potentially risky commands like
node -eordefaults writeare used in a controlled manner for version detection and simulator state management. - [SAFE]: The skill uses local execution of Python scripts for design matching and pixel sampling (e.g., using Pillow/numpy), but these are utility scripts provided within the skill's instructions for the developer's use and do not process untrusted external code.
Audit Metadata