centrifugo
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides legitimate documentation and integration examples for Centrifugo real-time messaging server. It does not contain malicious code or instructions.
- [CREDENTIALS_UNSAFE]: Sensitive configuration parameters like secret keys and API keys are represented using safe placeholders such as "" and "<API_KEY>" throughout the documentation.
- [EXTERNAL_DOWNLOADS]: The skill recommends installing official and widely-used libraries from the Centrifugo ecosystem, such as "centrifuge" for Node.js and "pycent" for Python, which are standard for this service.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies an attack surface where the agent might process real-time messages from WebSocket channels. It specifies ingestion points in "references/client-sdk.md" and a capability inventory involving local server API calls in "SKILL.md". It provides clear guidance that all data must be validated by a backend before transmission, acting as a structural mitigation.
Audit Metadata