orb-webhooks
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines templates for webhooks processing untrusted external inputs. Ingestion points: Webhook request bodies are ingested via the
/webhooks/orbroute inexamples/express/src/index.js,examples/fastapi/main.py, andexamples/nextjs/app/webhooks/orb/route.ts. Boundary markers: Prompt-specific delimiters are not present since these are standalone application route examples rather than direct LLM instructions. Capability inventory: Code analysis shows no unsafe behaviors, subprocess calls, dynamic execution (eval), or file system writes across any script files. Sanitization: Proper cryptographic validation is performed using HMAC-SHA256 signature verification and timestamp freshness validation to ensure requests originate from a trusted source.
Audit Metadata