websocket-engineer
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface where untrusted data from WebSocket connections is processed and redistributed.
- Ingestion points: Untrusted data enters the context via
socket.on("message", ({ roomId, text }) => ...)handlers inSKILL.mdandreferences/patterns.md. - Boundary markers: The primary code examples do not implement delimiters or specific instructions to isolate or ignore instructions within the
textpayload during the broadcast phase. - Capability inventory: The skill utilizes the
io.to(roomId).emit()capability, which allows the agent/server to propagate received text to multiple connected users. - Sanitization: While the implementation templates in
SKILL.mdlack immediate sanitization, thereferences/security.mdfile provides correct guidance on usingsanitize-htmlandjoifor input validation and XSS prevention, suggesting the risk is recognized but delegated to the developer to implement.
Audit Metadata