websocket-engineer

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides comprehensive and secure implementation patterns for real-time systems. All external dependencies (Socket.IO, Express, Redis, etc.) are standard, well-known libraries for this domain.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No sensitive data access or exfiltration patterns were detected. The skill correctly instructs the user to use environment variables for secrets and explicitly warns against broadcasting sensitive data to unauthorized clients in the 'MUST NOT DO' section of SKILL.md.
  • [REMOTE_CODE_EXECUTION]: No remote code execution or suspicious download patterns were identified. All code provided in the references is for documentation and educational purposes.
  • [PROMPT_INJECTION]: There are no instructions that attempt to override system safety guidelines or bypass security constraints. The skill includes standard role definitions and workflows for a software engineering specialist.
  • [INDIRECT_PROMPT_INJECTION]: While the skill defines how to ingest untrusted data from WebSocket clients, it provides extensive documentation in references/security.md for mitigation, including input validation with Joi, HTML sanitization with sanitize-html, and robust authentication/authorization checks.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 07:07 AM
Security Audit — agent-trust-hub — websocket-engineer