paddle-webhooks
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or data exfiltration vectors were detected in the skill instructions or example code.
- [SAFE]: The skill implements robust security practices, including HMAC-SHA256 signature verification for webhook payloads and timing-safe comparisons to prevent timing attacks during validation.
- [SAFE]: All external dependencies (e.g.,
@paddle/paddle-node-sdk,paddle-python-sdk) and recommended tools (e.g.,hookdeck-cli) are official libraries or vendor-owned resources. - [SAFE]: Secret management follows best practices by using placeholders in documentation and environment variable examples, rather than hardcoding credentials.
Audit Metadata