hookdeck-event-gateway
Warn
Audited by Socket on Mar 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
This file is a documentation/metadata README for the Hookdeck Event Gateway skill. It describes expected and legitimate behavior for a webhook ingestion and delivery service. There is no executable code in the provided fragment that performs credential theft, remote execution, or exfiltration. The primary supply-chain risks are the usual ones: installing the Hookdeck CLI or adding skills via npx introduces trust in third-party code and creates a transitive installation chain. That risk is expected for this product but should be managed by verifying package sources, pinning versions, and reviewing code for any installed CLIs or skills before granting them high privileges.
Confidence: 80%Severity: 65%
Audit Metadata