websocket-security

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent on using various command-line tools for security assessments, such as wsrepl, sqlmap, and protoc. These are legitimate utilities in the context of penetration testing.
  • [EXTERNAL_DOWNLOADS]: Mentions the installation of the 'wsrepl' package using the pip package manager. This is a common practice for setting up specialized security tooling.
  • [DATA_EXFILTRATION]: Contains several JavaScript and Python code snippets demonstrating how data could be exfiltrated to an external domain (e.g., attacker.com) during an exploit. These examples are clearly labeled as proof-of-concept (PoC) patterns for laboratory or authorized testing environments to illustrate vulnerabilities like Cross-Site WebSocket Hijacking.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 01:24 PM
Security Audit — agent-trust-hub — websocket-security