websocket-engineer
Pass
Audited by Gen Agent Trust Hub on Mar 30, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides comprehensive and secure implementation patterns for real-time systems. All external dependencies (Socket.IO, Express, Redis, etc.) are standard, well-known libraries for this domain.
- [DATA_EXPOSURE_AND_EXFILTRATION]: No sensitive data access or exfiltration patterns were detected. The skill correctly instructs the user to use environment variables for secrets and explicitly warns against broadcasting sensitive data to unauthorized clients in the 'MUST NOT DO' section of
SKILL.md. - [REMOTE_CODE_EXECUTION]: No remote code execution or suspicious download patterns were identified. All code provided in the references is for documentation and educational purposes.
- [PROMPT_INJECTION]: There are no instructions that attempt to override system safety guidelines or bypass security constraints. The skill includes standard role definitions and workflows for a software engineering specialist.
- [INDIRECT_PROMPT_INJECTION]: While the skill defines how to ingest untrusted data from WebSocket clients, it provides extensive documentation in
references/security.mdfor mitigation, including input validation with Joi, HTML sanitization with sanitize-html, and robust authentication/authorization checks.
Audit Metadata