stream-chain
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a sequential multi-agent workflow where the output of one agent becomes the direct prompt context for the next, processing untrusted external data without isolation.
- Ingestion points: The skill (SKILL.md) describes workflows that ingest content from the local
src/directory, external API responses, CSV files, and git repository changes. - Boundary markers: There are no instructions or templates for using delimiters or explicit 'ignore embedded instructions' markers to separate untrusted data from the agent's instructions between chain steps.
- Capability inventory: The documented workflows involve filesystem modifications ('Apply refactoring'), code execution ('Verify refactored code'), and network interaction ('Extract data from API responses').
- Sanitization: The skill does not provide mechanisms or instructions for sanitizing, validating, or escaping the data as it flows through the streaming pipeline.
Audit Metadata