skills/aeondave/malskill/webhook-site/Gen Agent Trust Hub

webhook-site

Warn

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DATA_EXFILTRATION]: The skill facilitates the transmission of data to webhook.site and its dnshook.site subdomains. While intended for out-of-band application security testing (OAST), these platforms are third-party services that record all headers, bodies, and DNS queries, which may include sensitive tokens, cookies, or credentials.
  • [COMMAND_EXECUTION]: The skill provides instructions for using whcli exec, a command that spawns a local shell process for every inbound request received by the webhook token. This allows for automated local actions based on external network events.
  • [DYNAMIC_EXECUTION]: The whcli exec feature executes arbitrary local commands (e.g., whcli exec --command='/path/to/script.sh') where the execution is triggered by remote network traffic. This behavior creates a bridge between untrusted external data and local process execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes an attack surface where external, untrusted data can influence local command execution.
  • Ingestion points: Inbound HTTP requests (headers, query strings, and body) and DNS queries captured by the webhook.
  • Boundary markers: The documentation does not provide instructions for implementing boundary markers or input validation for the scripts executed via whcli exec.
  • Capability inventory: The skill enables shell command execution triggered by external inputs.
  • Sanitization: Metadata such as WH_USER_AGENT, WH_URL, and custom headers (WH_HEADER_<NAME>) are injected directly into the environment of the spawned command, which can lead to command injection if the target script uses these variables unsafely.
  • [EXTERNAL_DOWNLOADS]: The skill directs the user to install the whcli tool via npm install -g whcli or run it via Docker from ghcr.io/webhooksite/whcli.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — webhook-site