webhook-platform-design

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a set of design instructions for architecting a secure and reliable webhook platform. It advocates for critical security features such as HMAC-SHA256 signing of payloads and the use of timestamps to mitigate replay attacks, aligning with the Standard Webhooks specification.
  • [SAFE]: The instructions explicitly warn against common integration security failures, such as failing to verify signatures on every request, verifying against modified JSON bodies instead of raw data, and improper authentication middleware placement.
  • [SAFE]: The skill does not contain any executable scripts, binary files, or commands that interact with the host system. It is purely documentation-based and uses external URLs only to refer to established standards and legitimate documentation from industry leaders like Stripe and GitHub.
  • [SAFE]: Analysis of all metadata, reference files, and evaluation prompts revealed no evidence of obfuscation, hidden URLs, or attempts to bypass agent safety guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:17 PM
Security Audit — agent-trust-hub — webhook-platform-design