webhook-integration-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides educational content and implementation patterns for webhooks without any detected malicious patterns.
  • Content consists of documentation and code snippets for robust webhook integration.
  • [INDIRECT_PROMPT_INJECTION]: The skill designs systems to ingest external data from third-party providers.
  • Ingestion points: Flask handlers in references/provider-examples.md and SKILL.md that process request.json and request.data from external providers like Stripe, GitHub, and Slack.
  • Boundary markers: The provided patterns emphasize HMAC-SHA256 signature verification and timestamp checks as robust boundaries to ensure data authenticity and prevent replay attacks.
  • Capability inventory: The skill patterns focus on data processing, asynchronous queuing, and idempotent state updates; no dangerous capabilities such as arbitrary shell execution or unauthorized network exfiltration are included.
  • Sanitization: Cryptographic verification logic is consistently provided to ensure only legitimate payloads from trusted providers are processed by the application logic.
  • [EXTERNAL_DOWNLOADS]: The skill suggests using established third-party tools for local development and testing.
  • Evidence: references/testing-webhooks.md mentions standard developer tools such as ngrok, localtunnel (via npm install), and official CLI tools from Stripe and GitHub.
  • Evaluation: These are well-known services in the developer ecosystem and their official tools are appropriate for the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — webhook-integration-patterns