alipay-webhooks

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill demonstrates secure webhook processing by implementing mandatory RSA-SHA256 signature verification before handling any payload data.\n- [SAFE]: Key management instructions are aligned with security best practices, advocating for the use of environment variables and providing guidance on handling PEM-formatted keys safely.\n- [SAFE]: The implementation examples correctly handle the raw request body, which is essential for accurate signature validation in the Alipay scheme.\n- [SAFE]: All identified dependencies are reputable, industry-standard libraries used for their intended cryptographic or web-server functionalities.\n- [SAFE]: The use of the vendor-provided utility tool (hookdeck-cli) for local testing is transparent and appropriate for the skill's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 07:05 AM
Security Audit — agent-trust-hub — alipay-webhooks