twilio-webhooks

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides integration guides and code templates for receiving Twilio communications events securely. No malicious code or hidden instructions were found across the example files or references.
  • [EXTERNAL_DOWNLOADS]: Dependencies are restricted to official package registries and well-known libraries such as twilio, express, and fastapi. The skill also references the hookdeck-cli, a utility provided by the skill's author for local development.
  • [COMMAND_EXECUTION]: Documentation provides standard developer commands for environment setup, dependency installation, and running provided test suites in Node.js and Python.
  • [INDIRECT_PROMPT_INJECTION]: While the skill defines endpoints for ingesting external webhook data, it enforces strict security boundaries by prioritizing signature verification.
  • Ingestion points: POST request bodies containing Twilio event parameters (e.g., MessageSid, Body) in examples/express/src/index.js, examples/fastapi/main.py, and examples/nextjs/app/webhooks/twilio/route.ts.
  • Boundary markers: Explicitly mandates and provides implementations for X-Twilio-Signature verification using HMAC-SHA1.
  • Capability inventory: Logic is restricted to logging communication metadata, routing by parameter shape, and returning TwiML (XML) responses.
  • Sanitization: All provided examples verify the signature before processing the request body, effectively ensuring that only authentic payloads from Twilio are processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:39 PM
Security Audit — agent-trust-hub — twilio-webhooks