webhooks
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of architectural and implementation guidelines for webhooks. It does not contain any executable code, scripts, or network operations.
- [SAFE]: The provided instructions promote industry-standard security practices, including HMAC signature verification to ensure message authenticity, timestamp validation to prevent replay attacks, and the use of environment variables for secret management.
- [SAFE]: The skill specifically warns against common vulnerabilities, such as logging PII (Personally Identifiable Information) and susceptibility to SSRF (Server-Side Request Forgery) when handling arbitrary user-defined URLs.
Audit Metadata