clerk-webhooks

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security risks identified. The skill promotes secure development practices for webhook handling by mandating cryptographic signature verification.\n- [INDIRECT_PROMPT_INJECTION]: The skill implements a secure pattern for handling external data ingestion.\n
  • Ingestion points: Webhook request payloads in framework-specific route handlers (e.g., app/api/webhooks/route.ts).\n
  • Boundary markers: The code examples mandate the use of official verifyWebhook adapters, which cryptographically validate the authenticity and integrity of the payload using a signing secret before any data is processed.\n
  • Capability inventory: Database operations via Prisma (db.users.create, db.workspaces.create), email dispatch via Resend (resend.emails.send), and external notifications via Slack webhooks (fetch).\n
  • Sanitization: Input is verified against the CLERK_WEBHOOK_SIGNING_SECRET before processing, ensuring only trusted data from Clerk is acted upon.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — clerk-webhooks