clerk-webhooks
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security risks identified. The skill promotes secure development practices for webhook handling by mandating cryptographic signature verification.\n- [INDIRECT_PROMPT_INJECTION]: The skill implements a secure pattern for handling external data ingestion.\n
- Ingestion points: Webhook request payloads in framework-specific route handlers (e.g.,
app/api/webhooks/route.ts).\n - Boundary markers: The code examples mandate the use of official
verifyWebhookadapters, which cryptographically validate the authenticity and integrity of the payload using a signing secret before any data is processed.\n - Capability inventory: Database operations via Prisma (
db.users.create,db.workspaces.create), email dispatch via Resend (resend.emails.send), and external notifications via Slack webhooks (fetch).\n - Sanitization: Input is verified against the
CLERK_WEBHOOK_SIGNING_SECRETbefore processing, ensuring only trusted data from Clerk is acted upon.
Audit Metadata