knock-webhooks

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill implements robust security practices for webhook handling, including HMAC-SHA256 signature verification and timing-safe equality checks using crypto.timingSafeEqual in Node.js and hmac.compare_digest in Python. It also correctly includes timestamp-based replay protection with a recommended 5-minute tolerance window, accounting for Knock's specific use of milliseconds for timestamps.
  • [EXTERNAL_DOWNLOADS]: The documentation and example READMEs recommend the use of the hookdeck-cli tool for local development and testing. This tool is provided by the skill's author (Hookdeck) and is a standard utility for facilitating webhook debugging and local tunneling.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:09 AM
Security Audit — agent-trust-hub — knock-webhooks