hunt-websocket

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed as a technical guide for security researchers to evaluate WebSocket security. It uses standard reconnaissance and testing methodologies aligned with industry best practices.
  • [COMMAND_EXECUTION]: The skill employs common shell utilities such as grep, curl, and nmap, as well as specialized tools like wscat, to perform security testing against a defined $TARGET. These operations are transparent and consistent with the skill's stated purpose of vulnerability hunting.
  • [EXTERNAL_DOWNLOADS]: The skill recommends the installation of wscat via the Node Package Manager (NPM) and websocat via Homebrew. These are legitimate, widely-recognized open-source tools for WebSocket interaction and testing.
  • [DATA_EXFILTRATION]: The Cross-Site WebSocket Hijacking (CSWSH) proof-of-concept includes a method for sending data to a Burp Collaborator domain (oastify.com). This is a standard, non-malicious technique used in professional security auditing to provide out-of-band proof of a vulnerability's impact.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 12:18 PM
Security Audit — agent-trust-hub — hunt-websocket