streamdown
Fail
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: CRITICAL
Full Analysis
- [SAFE]: Indirect Prompt Injection: The skill provides instructions for a library intended to render untrusted AI-generated content. The library mitigates these risks by defaulting to strict sanitization using
rehype-sanitizeand providing tools for protocol and domain whitelisting. - [DATA_EXFILTRATION]: The library references a default CDN URL (
https://streamdown.ai/cdn) for retrieving assets. This is a vendor-owned domain used for standard library features. - [EXTERNAL_DOWNLOADS]: The documentation guides the installation of standard development dependencies (
streamdown,shiki,katex) through official package registries. - [SAFE]: Automated alerts regarding 'your-domain.com' are identified as benign documentation placeholders used in code snippets demonstrating how to restrict links to a developer's own domain.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata