receiving-webhooks
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purely instructional and provides security-best-practice guidance for handling untrusted data from external webhook providers.- [EXTERNAL_DOWNLOADS]: Mentions official libraries (
standardwebhooks,svixSDK) and references documentation from the author's own infrastructure and open standards as part of the recommended secure implementation.- [CREDENTIALS_UNSAFE]: No hardcoded credentials were found; the instructions correctly emphasize keeping signing secrets server-side and distinct from API management tokens.- [DATA_EXFILTRATION]: No unauthorized data access or external transmission was identified; the logic focuses on verifying inbound requests.- [PROMPT_INJECTION]: No malicious instructions aimed at overriding agent behavior or extracting system prompts were detected.
Audit Metadata