hunt-websocket

Fail

Audited by Snyk on Aug 10, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The document contains explicit, actionable instructions for cross-site WebSocket hijacking, token/credential theft, real-time data exfiltration to external collaborators, and handshake smuggling—techniques directly enabling unauthorized data theft and remote abuse.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). The runtime workflow described in SKILL.md is a manual/active WebSocket security testing procedure (e.g., probing endpoints with curl, running custom wscat PoCs, and reading responses from the target you actively test), rather than an agent that ingests outsider-authored free text without selecting specific attacker-provided content.

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 10, 2026, 12:30 PM
Issues
2
Security Audit — snyk — hunt-websocket