paystack-webhooks

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructional content and code snippets for handling Paystack webhooks in Next.js and Express.js. All behaviors align with the stated purpose and follow industry security best practices.
  • [SAFE]: Implements HMAC SHA512 signature validation using standard libraries (crypto), ensuring authenticity of incoming webhook events.
  • [SAFE]: Provides official Paystack IP addresses for whitelisting (52.31.139.75, 52.49.173.169, 52.214.14.220), which is a recommended security layer.
  • [SAFE]: Promotes secure secret management by referencing environment variables (process.env.PAYSTACK_SECRET_KEY) rather than hardcoding credentials.
  • [SAFE]: Includes guidance on idempotency and asynchronous processing to improve reliability and prevent common webhook failure modes like timeouts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 01:19 PM
Security Audit — agent-trust-hub — paystack-webhooks