websocket-engineer
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: CRITICALMETADATA_POISONINGEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [METADATA_POISONING]: The main skill file (
SKILL.md) was flagged by file reputation scanners as malicious (FileRepMalware). - [EXTERNAL_DOWNLOADS]: The Documentation link (
https://jeffallan.github.io/claude-skills/skills/api-architecture/websocket-engineer/) is blacklisted by automated URL scanners (URL:Blacklist). - [COMMAND_EXECUTION]: The core workflow instructs users to run
npx wscat, which executes code directly from the npm registry. - [REMOTE_CODE_EXECUTION]: Given the malicious file reputation and blacklisted documentation links, the recommendation to execute external binaries via
npxis a high-risk remote code execution vector.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata