websocket-engineer
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill documentation and provided code snippets follow industry-standard practices for real-time systems. All sensitive configurations, such as JWT secrets and database URLs, are managed via environment variables rather than being hardcoded.- [COMMAND_EXECUTION]: The core workflow recommends using
npx wscatfor testing local WebSocket connections. This is a standard developer tool used for debugging and protocol verification.- [PROMPT_INJECTION]: The skill addresses the ingestion of untrusted external data through WebSocket messages and provides robust documentation for mitigating potential injection attacks. - Ingestion points: WebSocket message event listeners in
SKILL.mdandreferences/security.md. - Boundary markers: The guidance emphasizes the use of rooms and logical namespaces to scope message delivery.
- Capability inventory: The skill focus is restricted to software architecture and implementation, without requesting or utilizing dangerous host-level capabilities for the agent.
- Sanitization: The
references/security.mdfile provides clear examples of sanitizing user input usingsanitize-htmland validating data structures withJoi.
Audit Metadata