websockets-realtime

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill includes code patterns for ingesting and processing external data via WebSockets and SSE. While these interfaces handle untrusted data, the provided examples use industry-standard sanitization (JSON parsing with error handling) and enforce authentication before connection upgrades, minimizing the risk of prompt-based exploitation in the resulting implementations.- [EXTERNAL_DOWNLOADS]: The reference materials mention standard, well-known Node.js packages including 'ws' and 'ioredis'. These are standard components for real-time networking and data persistence in JavaScript environments and are documented neutrally for instructional purposes.- [COMMAND_EXECUTION]: No shell command execution or subprocess spawning was detected. The skill is restricted to application-layer networking and state management patterns.- [DATA_EXFILTRATION]: The skill demonstrates how to transmit data between clients and servers using WebSockets; however, these are architectural examples for building applications and do not involve unauthorized exfiltration of the user's environment data or sensitive local files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 11:04 AM
Security Audit — agent-trust-hub — websockets-realtime