webhooks
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/verify.shfile contains shell commands intended for local project linting. The analysis indicates these are defensive, heuristic search patterns (usinggrepandfind) designed to detect insecure coding practices in a user's own codebase. The script is read-only and does not perform network operations or execute untrusted data. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process inbound webhook data, which is an external and untrusted source. However, the skill explicitly mandates strict verification protocols: raw-body HMAC signature validation, timestamp window checks, and idempotency filtering. These controls effectively prevent malicious payloads from influencing the agent's logic before authentication.
- [CREDENTIALS_UNSAFE]: The skill correctly instructs the user to source signing secrets from environment variables and explicitly warns against hard-coding literals in source code. No hard-coded secrets were found within the skill itself.
- [DATA_EXFILTRATION]: There are no patterns suggesting the exfiltration of sensitive data. The network operations described (receiving POST requests) are the primary purpose of the skill, and the guidance focuses on rejecting unauthorized traffic.
Audit Metadata