hunt-websocket
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill documents standard redteam methodology for WebSocket security testing, including the use of common tools like curl, nmap, and wscat for reconnaissance.
- [SAFE]: The provided proof-of-concept for Cross-Site WebSocket Hijacking (CSWSH) correctly implements verification via Out-of-Band (OAST) techniques, which is a standard industry practice for validating impact.
- [SAFE]: Security tests for socket.io and SignalR are technically sound and target specific, well-known protocol-level authorization issues.
- [SAFE]: The skill includes explicit validation criteria to help users distinguish between legitimate findings and false positives.
Audit Metadata