intercom-deploy-integration

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructions for using well-known, legitimate deployment platforms including Vercel, Fly.io, and Google Cloud Run.
  • [SAFE]: Security best practices for secret management are enforced by guiding users to use platform-specific secret stores (e.g., Google Secret Manager, Fly secrets) rather than hardcoding sensitive API tokens or webhook secrets.
  • [SAFE]: The reference implementation for the Intercom webhook handler includes robust security checks, specifically verifying the HMAC-SHA1 signature and using timing-safe comparisons to protect against unauthorized requests and timing attacks.
  • [SAFE]: No malicious obfuscation, hidden instructions, or unauthorized data exfiltration patterns were detected in the skill's code or documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 03:23 AM
Security Audit — agent-trust-hub — intercom-deploy-integration