openai-webhooks

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is consistent with its stated purpose (verifying OpenAI webhook signatures and providing handler templates). I found no evidence of malicious behavior, credential exfiltration, obfuscation, or third-party proxying. There are a few correctness and robustness issues in the verification code (assumptions about secret encoding, lack of defensive checks before timingSafeEqual) that could cause failures or exceptions in edge cases, but these are implementation bugs rather than malicious patterns. Overall the code is benign but should be hardened before production use.

Confidence: 90%Severity: 15%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:30 PM
Package URL
pkg:socket/skills-sh/hookdeck%2Fwebhook-skills%2Fopenai-webhooks%2F@c85ebdb7ff9f8b025fd4a73d13dd6dd16721b310