websocket-engineer

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill documentation and provided code snippets follow industry-standard practices for real-time systems. All sensitive configurations, such as JWT secrets and database URLs, are managed via environment variables rather than being hardcoded.- [COMMAND_EXECUTION]: The core workflow recommends using npx wscat for testing local WebSocket connections. This is a standard developer tool used for debugging and protocol verification.- [PROMPT_INJECTION]: The skill addresses the ingestion of untrusted external data through WebSocket messages and provides robust documentation for mitigating potential injection attacks.
  • Ingestion points: WebSocket message event listeners in SKILL.md and references/security.md.
  • Boundary markers: The guidance emphasizes the use of rooms and logical namespaces to scope message delivery.
  • Capability inventory: The skill focus is restricted to software architecture and implementation, without requesting or utilizing dangerous host-level capabilities for the agent.
  • Sanitization: The references/security.md file provides clear examples of sanitizing user input using sanitize-html and validating data structures with Joi.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — websocket-engineer