ideogram-webhooks-events
Pass
Audited by Gen Agent Trust Hub on Mar 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides templates for implementing secure webhook endpoints.
- [SAFE]: Signature verification correctly utilizes
crypto.timingSafeEqualto mitigate timing attacks. - [SAFE]: Replay attack protection is implemented by validating the
x-ideogram-timestampheader against a 5-minute window. - [SAFE]: Sensitive information such as webhook secrets and Redis connection strings are managed via environment variables rather than being hardcoded.
- [SAFE]: External tools mentioned for testing (webhook.site, ngrok) are standard developer utilities and are used in an appropriate context.
Audit Metadata