hunt-websocket
Fail
Audited by Snyk on Aug 10, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The document contains explicit, actionable instructions for cross-site WebSocket hijacking, token/credential theft, real-time data exfiltration to external collaborators, and handshake smuggling—techniques directly enabling unauthorized data theft and remote abuse.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The runtime workflow described in SKILL.md is a manual/active WebSocket security testing procedure (e.g., probing endpoints with curl, running custom wscat PoCs, and reading responses from the target you actively test), rather than an agent that ingests outsider-authored free text without selecting specific attacker-provided content.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata