websocket-security

Warn

Audited by Gen Agent Trust Hub on Jul 4, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing external software from PyPI using pip install wsrepl in references/tooling.md. It also references a script named ws-harness.py that is not included in the provided file package.
  • [COMMAND_EXECUTION]: references/smuggling.md contains a Python script that utilizes the websocket library to create network connections and transmit raw binary data to targets. This is intended for demonstrating proxy bypass and smuggling techniques.
  • [DATA_EXFILTRATION]: references/handshake-cswsh.md provides functional JavaScript snippets designed to hijack WebSocket sessions and exfiltrate received message data to external domains such as attacker.com for educational and testing purposes.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 4, 2026, 02:08 PM
Security Audit — agent-trust-hub — websocket-security