webhook-reliability
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill correctly instructs developers to use environment variables for storing sensitive secrets instead of hardcoding them.
- [SAFE]: It promotes the use of timing-safe comparisons (timingSafeEqual) for signature verification, which prevents side-channel timing attacks.
- [SAFE]: The skill mandates signature verification as the first step in handling inbound webhooks, ensuring that unauthenticated payloads are not processed.
- [SAFE]: It provides explicit guidance on scrubbing PII and payment details from logs to prevent accidental data exposure.
- [SAFE]: No obfuscation, persistence mechanisms, or unauthorized network operations were found in the skill content.
Audit Metadata