cms-webhooks
Pass
Audited by Gen Agent Trust Hub on May 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is strictly advisory and does not include any executable code or scripts.
- [SAFE]: The
allowed-toolsfield in the frontmatter restricts the agent toRead,Grep, andGlobtools, ensuring it can only access information and cannot perform mutations, network requests, or command execution. - [SAFE]: The instructions explicitly include security mandates to never expose secrets, use environment variables, and validate signatures server-side.
- [SAFE]: There are no indicators of obfuscation, remote code downloads, persistence mechanisms, or privilege escalation attempts.
- [SAFE]: All external references and context relate to the vendor's own product (Contentstack) and infrastructure.
Audit Metadata