skills/joelhooks/joelclaw/webhooks/Gen Agent Trust Hub

webhooks

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements standard, secure patterns for handling webhooks, including HMAC-SHA256 and HMAC-SHA1 signature verification for various providers like Vercel, GitHub, and Stripe. It avoids hardcoding sensitive information by utilizing a dedicated secrets management tool (agent-secrets) for leasing API tokens and signing keys.
  • [INDIRECT_PROMPT_INJECTION]: The skill manages a pipeline where external data from webhooks is ingested and used to generate prompts for an agent. However, the documentation explicitly instructs developers to extract specific data fields rather than passing raw payloads, which serves as a primary sanitization measure. The ingestion points are clearly defined as /webhooks/:provider endpoints, and the skill provides a structured 3-step pattern (enrich -> build-prompt -> notify) to maintain boundary controls.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — webhooks