clerk-webhooks
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for processing external webhook data, which constitutes an ingestion surface for indirect prompt injection attacks.
- Ingestion points: Multiple webhook handlers in
SKILL.md(Next.js and Express) receive external request bodies from Clerk. - Boundary markers: The templates do not include delimiters or specific instructions to prevent the agent from being influenced by instructions embedded within user-supplied strings from the Clerk payload.
- Capability inventory: The handlers demonstrate the capability to perform database writes (
db.users.create), send automated emails via the Resend API, and post messages to Slack webhooks. - Sanitization: The examples interpolate data from the payload (such as names and emails) directly into database calls and Slack messages without explicit sanitization or validation logic shown in the documentation.
- [METADATA_POISONING]: The skill's metadata identifies the author as 'clerk', which contradicts the identified skill author 'midudev'. This represents an inconsistency in the skill identification fields.
Audit Metadata