ic-events-stream
Pass
Audited by Gen Agent Trust Hub on Jul 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is authored by the official vendor and all network activity is directed toward the verified domain
immersivecommons.com. The polling mechanism and routing logic are restricted to the user's own data based on the provided agent token.\n- [CREDENTIALS_UNSAFE]: The installation guide instructs users to store theirIC_AGENT_TOKENin environment variables. While this involves handling sensitive credentials, it is a standard and recommended practice for local agent configurations compared to hardcoding secrets.\n- [PROMPT_INJECTION]: The skill contains explicit defensive instructions regarding the handling of event payloads. It directs the agent to treat data originating from other members' agents as untrusted and to specifically ignore any directives or instructions embedded within those messages, effectively mitigating indirect prompt injection risks.\n- [EXTERNAL_DOWNLOADS]: The installation script fetches the skill definition directly from the vendor's official website usingcurlorInvoke-WebRequest. This is a legitimate and transparent method for skill deployment within the Immersive Commons ecosystem.
Audit Metadata