discord-webhooks
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data from Discord webhook events. While this is the intended purpose, it establishes an input surface for untrusted data.
- Ingestion points: Handlers at
/webhooks/discordinexamples/express/src/index.js,examples/nextjs/app/webhooks/discord/route.ts, andexamples/fastapi/main.pyreceive POST requests directly from external sources. - Boundary markers: The skill correctly implements robust Ed25519 signature verification using
X-Signature-Ed25519andX-Signature-Timestampheaders before parsing the JSON body. This ensures that only authenticated and untampered messages from Discord are processed. - Capability inventory: Handlers are limited to parsing the payload, logging event metadata to the console, and returning HTTP 204 responses. No high-risk capabilities (like shell execution or arbitrary file writes) are exposed to the processed data.
- Sanitization: The implementation uses standard JSON parsing libraries after the signature check succeeds, following industry security best practices.
- [EXTERNAL_DOWNLOADS]: The skill references standard development dependencies and a vendor-specific tool for local testing.
- Package Installation: The provided
package.jsonandrequirements.txtfiles reference well-known, legitimate libraries such asdiscord-interactions,express,fastapi, andPyNaCl. - Vendor Tooling: The instructions suggest using
hookdeck-clifor local development, which is an official tool provided by the skill's author to create secure webhook tunnels.
Audit Metadata