skills/vercel/streamdown/streamdown/Gen Agent Trust Hub

streamdown

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: CRITICALINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to render content generated by AI agents, which is considered untrusted data. By default, it enables raw HTML parsing through the rehype-raw plugin. While the skill also includes sanitization layers like rehype-sanitize and rehype-harden to mitigate risks, the ingestion of untrusted data combined with HTML rendering represents a potential surface for indirect prompt injection or layout manipulation if security configurations are bypassed or weakened.
  • External Resource Dependencies: The component is configured to use an external CDN (streamdown.ai) for delivering assets by default. Additionally, the skill documentation encourages the installation of several external npm packages (e.g., @streamdown/code, @streamdown/mermaid). Users should verify that these external endpoints and dependencies meet their project's security and privacy standards.
  • Automated Scan Reference: An automated security scan flagged assets/examples/custom-security.tsx as potentially malicious. However, a manual review of the file's content shows it consists of standard React code and security configuration settings for the rehype-harden plugin. The alert appears to be a heuristic detection triggered by the security-focused code patterns within the example file rather than an active threat.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 15, 2026, 07:37 AM
Security Audit — agent-trust-hub — streamdown