webhook-receiver-hardener

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [Prompt Injection] (SAFE): No instructions to override behavior or bypass safety filters were detected.
  • [Data Exposure & Exfiltration] (SAFE): No hardcoded secrets or unauthorized data access patterns were found. Use of environment variables for secrets follows best practices.
  • [Obfuscation] (SAFE): No encoded or hidden content was detected.
  • [Unverifiable Dependencies] (SAFE): No suspicious package installations or remote script executions were identified.
  • [Indirect Prompt Injection] (SAFE): The skill handles external webhook data via req.body but mitigates risks through mandatory HMAC SHA256 signature verification and idempotency checks using Redis.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:52 PM