streamdown
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: CRITICALINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- Indirect Prompt Injection Surface: The skill is designed to render content generated by AI agents, which is considered untrusted data. By default, it enables raw HTML parsing through the
rehype-rawplugin. While the skill also includes sanitization layers likerehype-sanitizeandrehype-hardento mitigate risks, the ingestion of untrusted data combined with HTML rendering represents a potential surface for indirect prompt injection or layout manipulation if security configurations are bypassed or weakened. - External Resource Dependencies: The component is configured to use an external CDN (
streamdown.ai) for delivering assets by default. Additionally, the skill documentation encourages the installation of several external npm packages (e.g.,@streamdown/code,@streamdown/mermaid). Users should verify that these external endpoints and dependencies meet their project's security and privacy standards. - Automated Scan Reference: An automated security scan flagged
assets/examples/custom-security.tsxas potentially malicious. However, a manual review of the file's content shows it consists of standard React code and security configuration settings for therehype-hardenplugin. The alert appears to be a heuristic detection triggered by the security-focused code patterns within the example file rather than an active threat.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata