stream-react

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches documentation from 'getstream.io' and installs official SDK packages from 'npmjs.com'. It also uses Playwright (from Microsoft) for UI verification. These are all well-known and trusted sources associated with the skill's primary purpose.
  • [COMMAND_EXECUTION]: Uses standard development tools (npm, npx, node) for scaffolding, package management, and starting a development server. Benign utility scripts are used for transparent tasks like renaming files or verifying installed dependencies.
  • [DATA_EXPOSURE]: The skill includes explicit rules to prevent the leakage of sensitive information. It instructs the agent never to read or edit '.env' files, uses the official 'getstream' CLI to manage environment variables securely, and ensures that sensitive files are added to '.gitignore'.
  • [DYNAMIC_EXECUTION]: The skill generates and executes local scripts for UI verification (screenshots and computed style probes). This is a contained, low-risk workflow designed to ensure visual fidelity without processing untrusted external inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 08:18 AM
Security Audit — agent-trust-hub — stream-react