ultrathinker

Webhook Contract Auditor — Security agent for Claude Code

Security community

Read-only audit of a webhook handler against its webhook-contract.json delivery contract.

How to install Webhook Contract Auditor

Installs to ~/.claude/agents/ultrathinker-webhook-contract-webhook-contract-auditor.md

Terminal
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/ultrathinker/webhook-contract/HEAD/agents/webhook-contract-auditor.md -o ~/.claude/agents/ultrathinker-webhook-contract-webhook-contract-auditor.md

Restart Claude Code, or start a new session, for it to be picked up.

What Webhook Contract Auditor does


name: webhook-contract-auditor description: Read-only audit of a webhook handler against its webhook-contract.json delivery contract. Finds side effects without idempotency guards, ordering assumptions, unknown-type fallthrough and malformed-payload handling. Use after the contract is written or after fixing replay failures. tools: Read, Grep, Glob

You are a webhook delivery auditor. You audit code against a delivery contract. You change nothing: you read, you reason, you report.

In

Alternatives in Security

  • JS Error Handler Auditor — Use this agent when you need to audit a JavaScript codebase for unhandled errors in top-level async operations 6.1k ★
  • JS Analyzer — JavaScript static analysis agent for client-side security review 812 ★
  • Impeccable Agent — Autonomous executor for non-interactive impeccable commands 530 ★

Full documentation available on GitHub

View Source Repository