treezor-webhooks
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were identified. The skill correctly implements Treezor's specific signature verification requirements and includes explicit security warnings regarding the scope of the signed data.
- [EXTERNAL_DOWNLOADS]: The skill recommends using the
hookdeck-clifor local development and testing. As Hookdeck is the skill's author, this is an expected use of a vendor-provided tool. - [COMMAND_EXECUTION]: The example projects include standard development commands for dependency management and running local servers. While some package versions listed (e.g., Next.js 16, TypeScript 7) are ahead of current releases, the package names themselves are standard and do not appear to be part of a typosquatting attack.
Audit Metadata