add-webhook
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the user to execute
modal deployto push orchestration logic to the Modal cloud platform. - [INDIRECT_PROMPT_INJECTION]: The skill establishes an infrastructure for event-driven execution that ingests data from external webhook triggers, creating a surface for indirect injection.
- Ingestion points: External HTTP requests targeted at the generated Modal webhook endpoints as described in
SKILL.md. - Boundary markers: The process lacks explicit delimiters or instructions for the agent to ignore potentially malicious commands embedded in the event data.
- Capability inventory: The resulting webhooks are granted access to sensitive tools including
send_email,read_sheet, andupdate_sheetas specified in thewebhooks.jsonconfiguration. - Sanitization: No input validation or sanitization logic is defined for the incoming payloads before they are processed by the agent orchestration logic.
Audit Metadata