zap-webhooks-routing-and-verification

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill exhibits coherent purpose-capability alignment: it provides a webhook routing/verification framework with HMAC-based security, schema validation, and an adapter pattern consistent with its description. The install/execution model relies on trusted in-repo libraries, with no evident unverifiable binaries or covert network calls. Data flows are appropriate for webhook processing, though care should be taken to avoid logging sensitive payload data and to ensure raw body handling is preserved for signature validation. Overall, the footprint is Benign with some modest security-conscious caveats (logging of payloads, secret handling) that can be mitigated with standard best practices.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 07:14 PM
Package URL
pkg:socket/skills-sh/zap-studio%2Fmonorepo%2Fzap-webhooks-routing-and-verification%2F@18064ce2796323c2e6191085a8ff56cb9c985f5d