websocket-engineer
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: LOW
Full Analysis
- Prompt Injection (SAFE): No instructions to override system prompts or bypass safety guidelines were found. The skill uses standard instructional language for defining a persona.\n- Data Exposure & Exfiltration (SAFE): No hardcoded secrets, sensitive local file paths, or network exfiltration commands are present.\n- Obfuscation (SAFE): The text is clear and does not utilize Base64, zero-width characters, or other encoding techniques to hide intent.\n- Unverifiable Dependencies & RCE (SAFE): The skill does not perform package installations or execute remote scripts. References to external libraries like Socket.IO and uWebSockets are for architectural context only.\n- Indirect Prompt Injection (LOW): The skill defines an interface for processing user-provided requirements to generate implementation code. While it lacks explicit boundary markers, it includes strong security constraints (e.g., mandatory authentication, avoiding broadcast of sensitive data) and does not possess autonomous execution or network capabilities that would elevate risk.
Audit Metadata