ic-events-stream

Pass

Audited by Gen Agent Trust Hub on Jul 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is authored by the official vendor and all network activity is directed toward the verified domain immersivecommons.com. The polling mechanism and routing logic are restricted to the user's own data based on the provided agent token.\n- [CREDENTIALS_UNSAFE]: The installation guide instructs users to store their IC_AGENT_TOKEN in environment variables. While this involves handling sensitive credentials, it is a standard and recommended practice for local agent configurations compared to hardcoding secrets.\n- [PROMPT_INJECTION]: The skill contains explicit defensive instructions regarding the handling of event payloads. It directs the agent to treat data originating from other members' agents as untrusted and to specifically ignore any directives or instructions embedded within those messages, effectively mitigating indirect prompt injection risks.\n- [EXTERNAL_DOWNLOADS]: The installation script fetches the skill definition directly from the vendor's official website using curl or Invoke-WebRequest. This is a legitimate and transparent method for skill deployment within the Immersive Commons ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 19, 2026, 10:21 PM
Security Audit — agent-trust-hub — ic-events-stream