add-webhook

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the user to execute modal deploy to push orchestration logic to the Modal cloud platform.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an infrastructure for event-driven execution that ingests data from external webhook triggers, creating a surface for indirect injection.
  • Ingestion points: External HTTP requests targeted at the generated Modal webhook endpoints as described in SKILL.md.
  • Boundary markers: The process lacks explicit delimiters or instructions for the agent to ignore potentially malicious commands embedded in the event data.
  • Capability inventory: The resulting webhooks are granted access to sensitive tools including send_email, read_sheet, and update_sheet as specified in the webhooks.json configuration.
  • Sanitization: No input validation or sanitization logic is defined for the incoming payloads before they are processed by the agent orchestration logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:55 PM