intercom-webhooks

Pass

Audited by Gen Agent Trust Hub on May 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill correctly implements security best practices for webhook verification. It uses Intercom's X-Hub-Signature header to perform HMAC-SHA1 validation against the raw request body. The implementation utilizes timing-safe comparison functions (crypto.timingSafeEqual in Node.js and hmac.compare_digest in Python) to prevent timing side-channel attacks.
  • [EXTERNAL_DOWNLOADS]: The documentation references hookdeck-cli via npx for local development and testing. This is a utility tool provided by the author (Hookdeck) to facilitate webhook debugging.
Audit Metadata
Risk Level
SAFE
Analyzed
May 13, 2026, 07:14 AM