Skip to content
Back to skills

Competition Websocket Runtime

ASecurity

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for WebSocket and SSE handshakes, auth material, subscription state, realtime message schemas, reconnect behavior, and frame-driven runtime effects. Use when the user asks to inspect a WebSocket or SSE handshake, decode frames, trace subscriptions, follow reconnect logic, inspect auth material sent during realtime setup, or explain how live frames change rendered or persisted state. Use only after `$ctf-sandbox-orche...

  • 34 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
ai-agentsgonodebackend

Works with

  • terminal

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add alicewe1/alice_skill --skill competition-websocket-runtime --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Competition Websocket Runtime?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Competition Websocket Runtime
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/alicewe1-competition-websocket-runtime/badge)](https://www.skillsdirectory.com/skills/alicewe1-competition-websocket-runtime)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: competition-websocket-runtime
description: Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for WebSocket and SSE handshakes, auth material, subscription state, realtime message schemas, reconnect behavior, and frame-driven runtime effects. Use when the user asks to inspect a WebSocket or SSE handshake, decode frames, trace subscriptions, follow reconnect logic, inspect auth material sent during realtime setup, or explain how live frames change rendered or persisted state. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
x-alice-class: assist
---

# Competition WebSocket Runtime

Use this skill only as a downstream specialization after `$ctf-sandbox-orchestrator` is already active and has established sandbox assumptions, node ownership, and evidence priorities. If that has not happened yet, return to `$ctf-sandbox-orchestrator` first.

Use this skill when the decisive behavior is carried by realtime handshake and frame flow rather than one-shot HTTP alone.

Reply in Simplified Chinese unless the user explicitly requests English.

## Quick Start

1. Map the handshake first: origin, path, headers, cookies, query, auth token, and upgrade response.
2. Separate connection setup, subscription messages, keepalives, server pushes, and reconnect logic.
3. Record message schema, topic or channel identity, and state side effects in one chain.
4. Tie frames to rendered, stored, or backend-visible effects.
5. Reproduce the smallest handshake-plus-frame sequence that reaches the decisive state change.

## Workflow

### 1. Map The Realtime Handshake

- Record the initial HTTP or SSE request, upgrade headers, cookies, tokens, query params, origin checks, and negotiated protocol.
- Note whether auth material is carried by headers, cookies, query strings, or initial application frames.
- Keep route, subscription endpoint, and session identity tied together.

### 2. Decode Message Flow

- Separate subscribe, unsubscribe, ack, heartbeat, server push, reconnect, and terminal frames.
- Recover message types, channel IDs, schema fields, and sequencing that matter to behavior.
- Distinguish transport keepalive from application-level business messages.

### 3. Reduce To The Decisive Realtime Path

- Compress the result to the smallest sequence: handshake -> auth or subscribe frame -> pushed or accepted frame -> resulting state change.
- Keep canonical frame order and any replayed minimal order side by side.
- If the hard part is generic protocol reassembly without runtime UI or app-state linkage, switch back to the tighter protocol skill.

## Read This Reference

- Load `references/websocket-runtime.md` for the handshake checklist, frame checklist, and evidence packaging.

## What To Preserve

- Handshake headers, cookies, query params, auth material, negotiated subprotocol, and channel IDs
- Frame schemas, subscription messages, server pushes, reconnect flow, and resulting state changes
- The smallest replayable realtime sequence that proves the decisive branch

Files in this skill

  • SKILL.md3 KB
  • agents/openai.yaml389 B
  • references/websocket-runtime.md989 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…