stream-react-native

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements strong security hygiene regarding credential management. It provides explicit rules and blueprints that guide developers to derive user identities server-side and use secure token providers instead of hardcoding secrets.
  • [SAFE]: External downloads are strictly limited to the vendor's official domain (getstream.io) and GitHub (raw.githubusercontent.com) for the purpose of retrieving documentation and migration guides. These are treated as trusted sources.
  • [SAFE]: Command execution is scoped to standard mobile development workflows (npm/yarn/npx, expo, pod install, xcrun). Potentially risky commands like node -e or defaults write are used in a controlled manner for version detection and simulator state management.
  • [SAFE]: The skill uses local execution of Python scripts for design matching and pixel sampling (e.g., using Pillow/numpy), but these are utility scripts provided within the skill's instructions for the developer's use and do not process untrusted external code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 08:19 AM
Security Audit — agent-trust-hub — stream-react-native