stripe-webhooks

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides boilerplate code and documentation for Stripe webhook integration. All code examples prioritize security by using official Stripe SDKs for signature verification.
  • [SAFE]: Webhook endpoints are correctly configured to use raw request bodies for signature validation, a critical requirement for preventing payload tampering.
  • [SAFE]: Recommendations for external tools, such as the Stripe CLI and Hookdeck CLI, refer to official and well-known developer services for local development and testing.
  • [SAFE]: Credential management guidance adheres to best practices by instructing users to use environment variables and providing .env.example templates with non-functional placeholders.
  • [SAFE]: The skill follows the principle of least privilege by focusing solely on the logic required to receive and handle asynchronous events from Stripe.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:04 AM
Security Audit — agent-trust-hub — stripe-webhooks