clerk-webhooks

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for processing external webhook data, which constitutes an ingestion surface for indirect prompt injection attacks.
  • Ingestion points: Multiple webhook handlers in SKILL.md (Next.js and Express) receive external request bodies from Clerk.
  • Boundary markers: The templates do not include delimiters or specific instructions to prevent the agent from being influenced by instructions embedded within user-supplied strings from the Clerk payload.
  • Capability inventory: The handlers demonstrate the capability to perform database writes (db.users.create), send automated emails via the Resend API, and post messages to Slack webhooks.
  • Sanitization: The examples interpolate data from the payload (such as names and emails) directly into database calls and Slack messages without explicit sanitization or validation logic shown in the documentation.
  • [METADATA_POISONING]: The skill's metadata identifies the author as 'clerk', which contradicts the identified skill author 'midudev'. This represents an inconsistency in the skill identification fields.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:19 PM
Security Audit — agent-trust-hub — clerk-webhooks