websocket-engineer
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions as a detailed engineering guide for WebSockets and Socket.IO, providing legitimate implementation patterns and architectural advice.
- [DATA_EXPOSURE]: Analysis of the code examples confirms that sensitive data such as JWT secrets and Redis connection strings are handled via environment variables (e.g.,
process.env.JWT_SECRET), which is standard secure practice. No hardcoded credentials or unauthorized access to sensitive local files were found. - [REMOTE_CODE_EXECUTION]: No remote script downloads, piped shell executions, or suspicious package installations were identified. The listed Node.js dependencies are all well-known, legitimate libraries for the stated purpose.
- [INDIRECT_PROMPT_INJECTION]: The skill correctly identifies the attack surface associated with processing external message data. It provides dedicated remediation guidance, including specific implementations for input validation using
Joiand XSS protection usingsanitize-htmlto prevent malicious payloads from impacting the system. - [OBFUSCATION]: The Base64 strings present in the documentation are standard protocol artifacts (WebSocket handshake keys) and do not contain hidden malicious commands.
Audit Metadata