skills/data-fair/lib/data-fair-ws/Gen Agent Trust Hub

data-fair-ws

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill serves as a technical guide for integrating @data-fair WebSocket libraries. All external dependencies are official vendor packages.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a system that ingests and processes real-time data from external clients, creating a potential surface for indirect prompt injection. The risk is mitigated by built-in authorization protocols.
  • Ingestion points: Data is received via useWS in the browser and WsClient in Node.js environments.
  • Boundary markers: The system utilizes a structured JSON protocol and implements a mandatory canSubscribe callback for server-side authorization.
  • Capability inventory: The provided code examples are restricted to the intended WebSocket communication and do not include high-risk capabilities like arbitrary command execution or local file system writes.
  • Sanitization: Authorization checks are enforced at the subscription level; specific data payload validation is expected to be handled by the application logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 03:50 PM
Security Audit — agent-trust-hub — data-fair-ws