webhook-site
Warn
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DATA_EXFILTRATION]: The skill facilitates the transmission of data to
webhook.siteand itsdnshook.sitesubdomains. While intended for out-of-band application security testing (OAST), these platforms are third-party services that record all headers, bodies, and DNS queries, which may include sensitive tokens, cookies, or credentials. - [COMMAND_EXECUTION]: The skill provides instructions for using
whcli exec, a command that spawns a local shell process for every inbound request received by the webhook token. This allows for automated local actions based on external network events. - [DYNAMIC_EXECUTION]: The
whcli execfeature executes arbitrary local commands (e.g.,whcli exec --command='/path/to/script.sh') where the execution is triggered by remote network traffic. This behavior creates a bridge between untrusted external data and local process execution. - [INDIRECT_PROMPT_INJECTION]: The skill describes an attack surface where external, untrusted data can influence local command execution.
- Ingestion points: Inbound HTTP requests (headers, query strings, and body) and DNS queries captured by the webhook.
- Boundary markers: The documentation does not provide instructions for implementing boundary markers or input validation for the scripts executed via
whcli exec. - Capability inventory: The skill enables shell command execution triggered by external inputs.
- Sanitization: Metadata such as
WH_USER_AGENT,WH_URL, and custom headers (WH_HEADER_<NAME>) are injected directly into the environment of the spawned command, which can lead to command injection if the target script uses these variables unsafely. - [EXTERNAL_DOWNLOADS]: The skill directs the user to install the
whclitool vianpm install -g whclior run it via Docker fromghcr.io/webhooksite/whcli.
Audit Metadata