stream-chain
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's architecture is built around sequential processing of data where the output of one step becomes the context for the next, creating a surface for injection attacks.
- Ingestion points: The skill documents ingestion of untrusted data from source code repositories ('Analyze codebase structure'), version control history ('Analyze recent git changes'), and external web services ('Extract data from API responses').
- Capability inventory: The skill has capabilities to modify the local filesystem ('Apply refactoring', 'Implement API endpoints') and execute network operations.
- Boundary markers: The documentation does not suggest the use of delimiters or 'ignore' instructions to isolate processed data from agent instructions.
- Sanitization: No sanitization or validation logic is mentioned for the data flowing through the pipeline.
- Gradual poisoning risk: The skill includes 'Neural Pattern Training' which stores results of successful chains to influence future performance, creating a potential vector for long-term poisoning of the agent's behavior.
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to perform state-changing operations on the host environment, such as applying refactored code and implementing new software features based on its analysis.
- [DATA_EXFILTRATION]: The skill workflows combine the extraction of potentially sensitive codebase information with external connectivity ('Enrich data with external API calls'), which could be exploited to exfiltrate data if the agent is manipulated into sending context to an unauthorized endpoint.
Audit Metadata