stream-chain

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a sequential multi-agent workflow where the output of one agent becomes the direct prompt context for the next, processing untrusted external data without isolation.
  • Ingestion points: The skill (SKILL.md) describes workflows that ingest content from the local src/ directory, external API responses, CSV files, and git repository changes.
  • Boundary markers: There are no instructions or templates for using delimiters or explicit 'ignore embedded instructions' markers to separate untrusted data from the agent's instructions between chain steps.
  • Capability inventory: The documented workflows involve filesystem modifications ('Apply refactoring'), code execution ('Verify refactored code'), and network interaction ('Extract data from API responses').
  • Sanitization: The skill does not provide mechanisms or instructions for sanitizing, validating, or escaping the data as it flows through the streaming pipeline.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:12 AM
Security Audit — agent-trust-hub — stream-chain