websocket
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides patterns and instructions for ingesting untrusted data from external clients via WebSocket connections. This creates a potential surface for indirect prompt injection if the data is later interpolated into prompts or used to drive agent logic without sufficient boundaries.
- Ingestion points: The skill references "websocket.receive_json()" in "SKILL.md" and "references/security-examples.md" as the primary entry point for external data.
- Boundary markers: The skill does not explicitly define prompt boundary markers for the data it processes, although it heavily documents data validation steps.
- Capability inventory: The provided code examples include capabilities for database interaction ("db.execute" in "references/threat-model.md") and authorized action handling.
- Sanitization: The skill emphasizes the use of Pydantic for strict schema validation ("WebSocketMessage(**data)") and provides logic for per-message authorization.
Audit Metadata