stream-unreal

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches the Stream Chat plugin from the official GetStream/stream-chat-unreal GitHub repository using the gh command-line tool. This operation is verified as originating from the vendor's own infrastructure.
  • [COMMAND_EXECUTION]: The skill executes standard build and project discovery commands, including the vendor's getstream CLI, the just command runner, and Unreal Engine's Build.sh and RunUAT.sh utilities.
  • [PROMPT_INJECTION]: The skill ingests data from external vendor documentation. Ingestion points: Remote documentation fetched from getstream.io (SKILL.md). Boundary markers: None. Capability inventory: Shell execution (bash, gh, getstream) and file operations across all integration scripts. Sanitization: Not applicable for static documentation fetching. This is a standard functional requirement for documentation orchestration and is considered safe given the trusted source.
  • [SAFE]: The documentation provides explicit security guidance, such as instructing users to avoid hardcoding API secrets and production tokens in project source files or configuration.
  • [SAFE]: Network activity is limited to the vendor's domains and GitHub through the allowed-tools configuration, preventing connections to unauthorized external sites.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 07:05 AM
Security Audit — agent-trust-hub — stream-unreal