

Also from Kynth Studios


Also from Kynth Studios
Audit worca webhook and chat integrations code for security — HMAC signing/verification correctness, timing-safe comparison usage, allowlist enforcement,…
Works
40% of the score100/100
Maintained
25% of the score100/100
Adopted
20% of the score20/100
Documented
15% of the score81/100
Audit worca webhook and chat integrations code for security — HMAC signing/verification correctness, timing-safe comparison usage, allowlist enforcement, env-var secret hygiene (never inline), rate-limit/retry boundary conditions, and the strict_inbox_verification opt-in. Distinct from worca-dispatch-governance-reviewer (which targets agent/skill dispatch). Dispatch after changes to `src/worca/events/webhook.py`, `worca-ui/server/webhook-inbox.js`, anything under `worca-ui/server/integrations/`, or webhook config schemas. Examples: <example>user: "I rewrote verify.js to support multiple secrets, please security-review."\nassistant: "Dispatching worca-integrations-security-reviewer to audit HMAC handling and timing-safe compare usage."</example> <example>user: "Are the new Slack adapter changes secure?"\nassistant: "Running worca-integrations-security-reviewer on the diff."</example>
| Artifact | Score | What the check found | Type | Reach | Last commit |
|---|---|---|---|---|---|
| worca-event-payload-reviewerSinishaDjukic/worca-cc | 81 | clean | Subagent | 30 stars | today |
| worca-release-preflightSinishaDjukic/worca-cc | 81 | clean | Subagent | 30 stars | today |
| worca-ui-a11y-reviewerSinishaDjukic/worca-cc | 81 | clean | Subagent | 30 stars | today |
| worca-ui-routing-reviewerSinishaDjukic/worca-cc | 81 | clean | Subagent | 30 stars | today |
| worca-ui-add-cardSinishaDjukic/worca-cc | 81 | clean | Skill | 30 stars | today |
| worca-templateSinishaDjukic/worca-cc | 81 | clean | Skill | 30 stars | today |
| Artifact | Score | What the check found | Category | Reach | Last commit |
|---|---|---|---|---|---|
| security-revieweraffaan-m/ECC | 90 | clean | Security | 242k stars | yesterday |
| security-compliance-security-auditorwshobson/agents | 89 | clean | Security | 39k stars | 3 days ago |
| security-scanning-security-auditorwshobson/agents | 89 | clean | Security | 39k stars | 3 days ago |
| security-auditoraddyosmani/agent-skills | 89 | clean | Security | 89k stars | today |
| security-auditoranthropics/claude-plugins-official | 88 | clean | Security | 34k stars | today |
| 3-tu-compiler-analyzertrailofbits/skills | 88 | clean | Security | 6.8k stars | today |
A badge carrying how many listings this index holds from the repository and how many pass every static structural check. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
[](https://skillworks.kynth.studio/?q=SinishaDjukic%2Fworca-cc)Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.


Also from Kynth Studios