stream-swift

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill employs the getstream CLI for essential development tasks like environment setup and user authentication. \n
  • Evidence: Commands such as getstream init, getstream env, and getstream token are used in setup.md and push.md to configure the developer environment. \n
  • These operations are performed using the official vendor tool and the instructions explicitly warn against hardcoding secrets. \n- [DYNAMIC_EXECUTION]: The skill provides Python and ImageMagick scripts to perform image analysis for UI design fidelity. \n
  • Evidence: design-matching.md contains a Python snippet using PIL and numpy to calculate icon dimensions and color values from screenshots. \n
  • These scripts are standard utilities for developers and do not perform unauthorized system or network operations. \n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted design references which could potentially contain malicious instructions. \n
  • Ingestion points: User-provided screenshots and Figma links in design-matching.md and SKILL.md. \n
  • Boundary markers: Present; the skill uses a strict classification and grounding process (SKILL.md Step 0 and Step 1) to validate requests against official documentation. \n
  • Capability inventory: The skill has file writing, network fetching (WebFetch), and CLI execution (Bash) capabilities. \n
  • Sanitization: The instructions mandate the use of named constants and configuration files for sensitive data, and provide rigorous verification steps to iterate on UI renders.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 08:19 AM
Security Audit — agent-trust-hub — stream-swift