webhook-receivers
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill offers standard technical guidance for implementing secure webhook receivers, including recommendations for using
crypto.timingSafeEqualand proper status code management. - [INDIRECT_PROMPT_INJECTION]: The skill involves instructions for processing untrusted external data (webhooks). Ingestion points: Next.js Route Handlers. Boundary markers: Not applicable (informational guidelines). Capability inventory: Uses
repo-filesfor repository access. Sanitization: Instructions mandate signature verification and raw body integrity checks. - [EXTERNAL_DOWNLOADS]: The skill references the author's GitHub repository and npm package in the footer. These are static links to vendor resources used for reference and do not involve automated downloads or remote code execution.
Audit Metadata