webhook-integration-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides educational content and implementation patterns for webhooks without any detected malicious patterns.
- Content consists of documentation and code snippets for robust webhook integration.
- [INDIRECT_PROMPT_INJECTION]: The skill designs systems to ingest external data from third-party providers.
- Ingestion points: Flask handlers in
references/provider-examples.mdandSKILL.mdthat processrequest.jsonandrequest.datafrom external providers like Stripe, GitHub, and Slack. - Boundary markers: The provided patterns emphasize HMAC-SHA256 signature verification and timestamp checks as robust boundaries to ensure data authenticity and prevent replay attacks.
- Capability inventory: The skill patterns focus on data processing, asynchronous queuing, and idempotent state updates; no dangerous capabilities such as arbitrary shell execution or unauthorized network exfiltration are included.
- Sanitization: Cryptographic verification logic is consistently provided to ensure only legitimate payloads from trusted providers are processed by the application logic.
- [EXTERNAL_DOWNLOADS]: The skill suggests using established third-party tools for local development and testing.
- Evidence:
references/testing-webhooks.mdmentions standard developer tools such asngrok,localtunnel(vianpm install), and official CLI tools from Stripe and GitHub. - Evaluation: These are well-known services in the developer ecosystem and their official tools are appropriate for the skill's stated purpose.
Audit Metadata