websocket-security
Warn
Audited by Gen Agent Trust Hub on Jul 4, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing external software from PyPI using
pip install wsreplinreferences/tooling.md. It also references a script namedws-harness.pythat is not included in the provided file package. - [COMMAND_EXECUTION]:
references/smuggling.mdcontains a Python script that utilizes thewebsocketlibrary to create network connections and transmit raw binary data to targets. This is intended for demonstrating proxy bypass and smuggling techniques. - [DATA_EXFILTRATION]:
references/handshake-cswsh.mdprovides functional JavaScript snippets designed to hijack WebSocket sessions and exfiltrate received message data to external domains such asattacker.comfor educational and testing purposes.
Audit Metadata