Skip to main content

auditing-websocket-connection-trust

Audit a WebSocket endpoint for trust established once at the handshake and never re-checked, so a cross-site page or a post-handshake message drives a privileged action, after the origin check and the credential source are resolved. Covers a missing or always-true origin check on the upgrade with ambient-cookie authentication, authentication at the handshake with no per-message authorization, a message treated as transport into a downstream injection sink, an unbounded frame or connection allowance inviting denial of service, tunneling past HTTP-layer controls that inspect only the request, and sensitive data broadcast to under-scoped subscribers. Use when reviewing the upgrade handler, the per-message dispatch, and the origin and credential checks, not the wss certificate validation the transport skill owns. A cross-origin or unauthenticated handshake is the source, a privileged action reached over the socket is the sink, and trust checked only at the upgrade is the bug.

الانتقال إلى التثبيت

معلومات المصدر

المستودع
UnboundCompute/security-agent-skills
آخر نشاط في المصدر
٢٥ أغسطس ٢٠٢٦ في ١٨:٢٤
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
٤
التفرعات
٢

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.