websocket-engineer

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: CRITICALMETADATA_POISONINGEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [METADATA_POISONING]: The main skill file (SKILL.md) was flagged by file reputation scanners as malicious (FileRepMalware).
  • [EXTERNAL_DOWNLOADS]: The Documentation link (https://jeffallan.github.io/claude-skills/skills/api-architecture/websocket-engineer/) is blacklisted by automated URL scanners (URL:Blacklist).
  • [COMMAND_EXECUTION]: The core workflow instructs users to run npx wscat, which executes code directly from the npm registry.
  • [REMOTE_CODE_EXECUTION]: Given the malicious file reputation and blacklisted documentation links, the recommendation to execute external binaries via npx is a high-risk remote code execution vector.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 15, 2026, 06:45 AM
Security Audit — agent-trust-hub — websocket-engineer