qe-stream-chain

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to create pipelines where data flows between agents, creating a significant attack surface for instructions embedded in processed data.
  • Ingestion points: The documentation describes workflows that read from the 'src/' directory, 'API responses', and 'CSV files' (SKILL.md).
  • Boundary markers: Example prompts such as 'Extract data from API responses' and 'Analyze authentication.js' do not include delimiters or instructions to disregard potential commands found within that data.
  • Capability inventory: The skill's orchestrated actions include high-impact capabilities such as 'Apply refactoring' (potentially modifying source code) and making 'external API calls' (network access) (SKILL.md).
  • Sanitization: The instructions do not specify any validation or sanitization steps for data moving through the stream-chain, allowing potentially malicious content to influence the behavior of agents later in the sequence.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:16 PM
Security Audit — agent-trust-hub — qe-stream-chain