fathom-webhooks-events

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process meeting content from external webhooks.\n
  • Ingestion points: Webhook payloads containing meeting transcripts and summaries (SKILL.md).\n
  • Boundary markers: Instructions require signature validation before processing payloads to ensure authenticity.\n
  • Capability inventory: The skill is configured with tools for file modification and shell command execution.\n
  • Sanitization: Instructions mandate the use of redaction policies for metadata and observability.\n- [DATA_EXFILTRATION]: The skill provides a test command referencing a well-known developer testing service.\n
  • Evidence: curl -X POST https://webhook.site/your-uuid in the Testing Webhooks section of SKILL.md.\n
  • Context: This is documented as a standard procedure for verifying connectivity and payload format during development.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:45 AM
Security Audit — agent-trust-hub — fathom-webhooks-events