skills/jeremylongshore/claude-code-plugins-plus-skills/coderabbit-webhooks-events/Gen Agent Trust Hub
coderabbit-webhooks-events
Pass
Audited by Gen Agent Trust Hub on Mar 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides implementation templates for webhook receivers that follow security best practices, specifically using timing-safe comparisons (
crypto.timingSafeEqual) for signature verification and validating the sender's identity. - [SAFE]: No hardcoded secrets, sensitive file access, or unauthorized network operations were identified. The use of environment variables for secrets is correctly recommended.
- [SAFE]: All provided code snippets and instructions align with the stated purpose of managing CodeRabbit events, with no signs of obfuscation, persistence mechanisms, or privilege escalation.
Audit Metadata