websocket-engineer

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface where untrusted data from WebSocket connections is processed and redistributed.
  • Ingestion points: Untrusted data enters the context via socket.on("message", ({ roomId, text }) => ...) handlers in SKILL.md and references/patterns.md.
  • Boundary markers: The primary code examples do not implement delimiters or specific instructions to isolate or ignore instructions within the text payload during the broadcast phase.
  • Capability inventory: The skill utilizes the io.to(roomId).emit() capability, which allows the agent/server to propagate received text to multiple connected users.
  • Sanitization: While the implementation templates in SKILL.md lack immediate sanitization, the references/security.md file provides correct guidance on using sanitize-html and joi for input validation and XSS prevention, suggesting the risk is recognized but delegated to the developer to implement.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 09:19 PM
Security Audit — agent-trust-hub — websocket-engineer