twilio-webhooks
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides integration guides and code templates for receiving Twilio communications events securely. No malicious code or hidden instructions were found across the example files or references.
- [EXTERNAL_DOWNLOADS]: Dependencies are restricted to official package registries and well-known libraries such as
twilio,express, andfastapi. The skill also references thehookdeck-cli, a utility provided by the skill's author for local development. - [COMMAND_EXECUTION]: Documentation provides standard developer commands for environment setup, dependency installation, and running provided test suites in Node.js and Python.
- [INDIRECT_PROMPT_INJECTION]: While the skill defines endpoints for ingesting external webhook data, it enforces strict security boundaries by prioritizing signature verification.
- Ingestion points: POST request bodies containing Twilio event parameters (e.g.,
MessageSid,Body) inexamples/express/src/index.js,examples/fastapi/main.py, andexamples/nextjs/app/webhooks/twilio/route.ts. - Boundary markers: Explicitly mandates and provides implementations for
X-Twilio-Signatureverification using HMAC-SHA1. - Capability inventory: Logic is restricted to logging communication metadata, routing by parameter shape, and returning TwiML (XML) responses.
- Sanitization: All provided examples verify the signature before processing the request body, effectively ensuring that only authentic payloads from Twilio are processed.
Audit Metadata