stripe-webhooks
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides boilerplate code and documentation for Stripe webhook integration. All code examples prioritize security by using official Stripe SDKs for signature verification.
- [SAFE]: Webhook endpoints are correctly configured to use raw request bodies for signature validation, a critical requirement for preventing payload tampering.
- [SAFE]: Recommendations for external tools, such as the Stripe CLI and Hookdeck CLI, refer to official and well-known developer services for local development and testing.
- [SAFE]: Credential management guidance adheres to best practices by instructing users to use environment variables and providing
.env.exampletemplates with non-functional placeholders. - [SAFE]: The skill follows the principle of least privilege by focusing solely on the logic required to receive and handle asynchronous events from Stripe.
Audit Metadata