skills/editframe/skills/webhooks/Gen Agent Trust Hub

webhooks

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional, providing developers with guidance on how to configure and verify webhooks for the Editframe platform.
  • [EXTERNAL_DOWNLOADS]: References the editframe CLI (via npx) and ngrok for local development. These are standard, well-known tools within the developer community and originate from trusted or vendor-aligned sources.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a system for processing external data (webhook payloads). It proactively addresses security by providing a reference implementation that uses HMAC-SHA256 signature verification with raw request bodies and constant-time comparison (crypto.timingSafeEqual) to prevent unauthorized payloads or timing attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:13 PM
Security Audit — agent-trust-hub — webhooks