debug-webhooks
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFE
Full Analysis
- [Data Interaction Surface]: The skill interacts with webhook configuration metadata, such as subscription topics, fields, and callback URLs. This is essential for its purpose of identifying misconfigurations in Meta applications.
- [Indirect Prompt Injection Surface]: The skill ingests data from external sources, specifically webhook subscription lists and test delivery responses. While this introduces a surface where external data enters the prompt context, the risk is addressed by requiring user confirmation before any corrective actions (like updating fields or resubscribing) are performed.
- [Authorized Tooling]: Usage is confined to the
mcp__devtoolsnamespace. The tools listed in the configuration are consistent with the skill's description and workflow, focusing on listing, testing, and managing application-level webhook settings.
Audit Metadata