data-fair-ws
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill serves as a technical guide for integrating @data-fair WebSocket libraries. All external dependencies are official vendor packages.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a system that ingests and processes real-time data from external clients, creating a potential surface for indirect prompt injection. The risk is mitigated by built-in authorization protocols.
- Ingestion points: Data is received via useWS in the browser and WsClient in Node.js environments.
- Boundary markers: The system utilizes a structured JSON protocol and implements a mandatory canSubscribe callback for server-side authorization.
- Capability inventory: The provided code examples are restricted to the intended WebSocket communication and do not include high-risk capabilities like arbitrary command execution or local file system writes.
- Sanitization: Authorization checks are enforced at the subscription level; specific data payload validation is expected to be handled by the application logic.
Audit Metadata