orb-webhooks

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines templates for webhooks processing untrusted external inputs. Ingestion points: Webhook request bodies are ingested via the /webhooks/orb route in examples/express/src/index.js, examples/fastapi/main.py, and examples/nextjs/app/webhooks/orb/route.ts. Boundary markers: Prompt-specific delimiters are not present since these are standalone application route examples rather than direct LLM instructions. Capability inventory: Code analysis shows no unsafe behaviors, subprocess calls, dynamic execution (eval), or file system writes across any script files. Sanitization: Proper cryptographic validation is performed using HMAC-SHA256 signature verification and timestamp freshness validation to ensure requests originate from a trusted source.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:08 AM
Security Audit — agent-trust-hub — orb-webhooks