Skip to main content

auditing-websocket-connection-trust

Audit a WebSocket endpoint for trust established once at the handshake and never re-checked, so a cross-site page or a post-handshake message drives a privileged action, after the origin check and the credential source are resolved. Covers a missing or always-true origin check on the upgrade with ambient-cookie authentication, authentication at the handshake with no per-message authorization, a message treated as transport into a downstream injection sink, an unbounded frame or connection allowance inviting denial of service, tunneling past HTTP-layer controls that inspect only the request, and sensitive data broadcast to under-scoped subscribers. Use when reviewing the upgrade handler, the per-message dispatch, and the origin and credential checks, not the wss certificate validation the transport skill owns. A cross-origin or unauthenticated handshake is the source, a privileged action reached over the socket is the sink, and trust checked only at the upgrade is the bug.

Jump to install

Source facts

Repository
UnboundCompute/security-agent-skills
Last source activity
August 25, 2026 at 18:24
Detected SKILL.md language
English
Stars
4
Forks
2

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.