hunt-websocket
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed as a technical guide for security researchers to evaluate WebSocket security. It uses standard reconnaissance and testing methodologies aligned with industry best practices.
- [COMMAND_EXECUTION]: The skill employs common shell utilities such as
grep,curl, andnmap, as well as specialized tools likewscat, to perform security testing against a defined$TARGET. These operations are transparent and consistent with the skill's stated purpose of vulnerability hunting. - [EXTERNAL_DOWNLOADS]: The skill recommends the installation of
wscatvia the Node Package Manager (NPM) andwebsocatvia Homebrew. These are legitimate, widely-recognized open-source tools for WebSocket interaction and testing. - [DATA_EXFILTRATION]: The Cross-Site WebSocket Hijacking (CSWSH) proof-of-concept includes a method for sending data to a Burp Collaborator domain (
oastify.com). This is a standard, non-malicious technique used in professional security auditing to provide out-of-band proof of a vulnerability's impact.
Audit Metadata