webhooks
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill implements standard, secure patterns for handling webhooks, including HMAC-SHA256 and HMAC-SHA1 signature verification for various providers like Vercel, GitHub, and Stripe. It avoids hardcoding sensitive information by utilizing a dedicated secrets management tool (agent-secrets) for leasing API tokens and signing keys.
- [INDIRECT_PROMPT_INJECTION]: The skill manages a pipeline where external data from webhooks is ingested and used to generate prompts for an agent. However, the documentation explicitly instructs developers to extract specific data fields rather than passing raw payloads, which serves as a primary sanitization measure. The ingestion points are clearly defined as
/webhooks/:providerendpoints, and the skill provides a structured 3-step pattern (enrich -> build-prompt -> notify) to maintain boundary controls.
Audit Metadata