skills/ericrisco/rsc-harness/webhooks/Gen Agent Trust Hub

webhooks

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/verify.sh file contains shell commands intended for local project linting. The analysis indicates these are defensive, heuristic search patterns (using grep and find) designed to detect insecure coding practices in a user's own codebase. The script is read-only and does not perform network operations or execute untrusted data.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process inbound webhook data, which is an external and untrusted source. However, the skill explicitly mandates strict verification protocols: raw-body HMAC signature validation, timestamp window checks, and idempotency filtering. These controls effectively prevent malicious payloads from influencing the agent's logic before authentication.
  • [CREDENTIALS_UNSAFE]: The skill correctly instructs the user to source signing secrets from environment variables and explicitly warns against hard-coding literals in source code. No hard-coded secrets were found within the skill itself.
  • [DATA_EXFILTRATION]: There are no patterns suggesting the exfiltration of sensitive data. The network operations described (receiving POST requests) are the primary purpose of the skill, and the guidance focuses on rejecting unauthorized traffic.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:56 AM
Security Audit — agent-trust-hub — webhooks