debug-webhooks

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFE
Full Analysis
  • [Data Interaction Surface]: The skill interacts with webhook configuration metadata, such as subscription topics, fields, and callback URLs. This is essential for its purpose of identifying misconfigurations in Meta applications.
  • [Indirect Prompt Injection Surface]: The skill ingests data from external sources, specifically webhook subscription lists and test delivery responses. While this introduces a surface where external data enters the prompt context, the risk is addressed by requiring user confirmation before any corrective actions (like updating fields or resubscribing) are performed.
  • [Authorized Tooling]: Usage is confined to the mcp__devtools namespace. The tools listed in the configuration are consistent with the skill's description and workflow, focusing on listing, testing, and managing application-level webhook settings.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 02:10 PM
Security Audit — agent-trust-hub — debug-webhooks