websocket-engineer

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides comprehensive and secure implementation examples for real-time communication. It explicitly advocates for security best practices such as JWT authentication, CORS configuration, and input validation. Specifically:
  • In SKILL.md and references/security.md, it demonstrates robust authentication middleware using jsonwebtoken to verify tokens before establishing connections.
  • It includes patterns for rate limiting (both local and distributed via Redis) to prevent denial-of-service attacks.
  • It provides examples of XSS protection using sanitize-html and input validation using Joi.
  • The architectural advice correctly identifies the need for sticky sessions and Redis pub/sub for horizontal scaling.
  • External links point to the author's official GitHub Pages documentation, which is a recognized and safe platform for skill documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:56 PM
Security Audit — agent-trust-hub — websocket-engineer