websocket-engineer

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a detailed engineering guide for WebSockets and Socket.IO, providing legitimate implementation patterns and architectural advice.
  • [DATA_EXPOSURE]: Analysis of the code examples confirms that sensitive data such as JWT secrets and Redis connection strings are handled via environment variables (e.g., process.env.JWT_SECRET), which is standard secure practice. No hardcoded credentials or unauthorized access to sensitive local files were found.
  • [REMOTE_CODE_EXECUTION]: No remote script downloads, piped shell executions, or suspicious package installations were identified. The listed Node.js dependencies are all well-known, legitimate libraries for the stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill correctly identifies the attack surface associated with processing external message data. It provides dedicated remediation guidance, including specific implementations for input validation using Joi and XSS protection using sanitize-html to prevent malicious payloads from impacting the system.
  • [OBFUSCATION]: The Base64 strings present in the documentation are standard protocol artifacts (WebSocket handshake keys) and do not contain hidden malicious commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:48 PM
Security Audit — agent-trust-hub — websocket-engineer