smile-webhooks
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides educational examples for implementing HMAC-SHA512 signature verification for webhooks, specifically using timing-safe comparisons to prevent side-channel attacks.
- [SAFE]: Secret management follows best practices by using environment variables and providing
.env.exampletemplates rather than hardcoding sensitive credentials. - [SAFE]: All identified dependencies in Node.js (Express, Next.js) and Python (FastAPI) are standard, well-known packages from official registries.
- [SAFE]: The mention of
hookdeck-cliis consistent with the skill's author ('hookdeck') and is provided as a legitimate tool for local development and testing. - [SAFE]: No prompt injection, obfuscation, or unauthorized data exfiltration patterns were found during the analysis.
Audit Metadata