stream-react

Warn

Audited by Socket on Sep 24, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is largely coherent with its stated purpose as a Stream React builder and uses mostly official vendor ecosystems, so it does not show confirmed malicious intent or credential-harvesting behavior. However, it expands trust through transitive skill installation, many autonomous shell/install actions, and several unpinned latest dependencies/downloads, which makes the overall footprint moderately risky for an AI agent skill.

Confidence: 88%Severity: 58%
SecurityMEDIUM
references/CROSS-PRODUCT.md

The fragment appears to be legitimate integration documentation rather than malware. Its significant security risk is the token endpoint design: it accepts a caller-controlled user identity, upserts that identity, and mints chat/video tokens without visible authentication or authorization. If publicly accessible without external route protection, this enables user impersonation and unauthorized account creation or modification. The call-related code shows no malicious behavior. The feed-token generation also appears potentially incorrect but is not evidence of malware.

Confidence: 94%Severity: 78%
Audit Metadata
Analyzed At
Sep 24, 2026, 08:20 AM
Package URL
pkg:socket/skills-sh/getstream%2Fagent-skills%2Fstream-react%2F@979aeaa416037769dbcbad241b4f3829ddd50b650a192dd1ea53c0cbef3cf93e
Security Audit — socket — stream-react