CtrlK
BlogDocsLog inGet started
Tessl Logo

rc-webhooks

Use this skill when consuming RevenueCat webhooks on your backend. Covers the normalized event schema, the full event type list, idempotency via the event id field, and the correct handling for CANCELLATION versus EXPIRATION versus RENEWAL.

73

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A high-quality, actionable skill body: executable code, a decision table that preempts real bugs, and a verification checklist. The two weaker spots are mild redundancy across the sample payloads and inlining reference-grade material (full event table, payload dumps) rather than splitting it into a bundle file.

Suggestions

Consolidate the three near-identical sample payloads (CANCELLATION, EXPIRATION, RENEWAL) into one payload example plus a short table of the fields that differ per event type, cutting significant duplicate tokens.

Move the full event-type table and the sample payloads into a references/event-types.md file and keep SKILL.md as a lean overview with well-signaled one-level-deep links.

Add a one-line note on how the signature is verified (e.g., HMAC-SHA256 of the raw body with the webhook secret) so the verifySignature stub is self-contained.

DimensionReasoningScore

Conciseness

Prose is lean and imperative with no padding explaining basics Claude already knows, but the three sample payloads (CANCELLATION, EXPIRATION, RENEWAL) repeat the same envelope shape almost field-for-field, which is noticeable redundancy that could be tightened. Efficient overall, so above the midpoint rather than at it.

4 / 5

Actionability

Provides near copy-paste Kotlin for the endpoint, signature check, atomic dedup, and full per-type dispatch, plus concrete implementation details ('a unique index on event_id plus an insert that swallows duplicate key errors', 'Do all downstream writes in the same transaction'). The examples cover the common and tricky cases including renewal-after-expiry.

5 / 5

Workflow Clarity

Clear Discover → Plan → Execute sequence with a decision table, explicit 'Key decisions' flagging the common revocation bugs, and a terminal Verification Checklist with concrete checks (replay no-op, CANCELLATION retains access, RENEWAL-after-EXPIRATION restores access). Validation checkpoints are explicit and actionable.

5 / 5

Progressive Disclosure

Sections are well organized with a single clearly signaled one-level-deep reference (the full chapter link) and no nested references. However, the ~195-line body inlines the full event-type table and several large JSON payloads that would fit naturally in a references/ file, which is a minor organization gap rather than a clear 5-way split.

4 / 5

Total

18

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it names the domain, lists concrete capabilities, and pairs them with an explicit 'Use this skill when' trigger clause using natural developer vocabulary. The only notable gap is omitting signature verification from the capability list.

DimensionReasoningScore

Specificity

Lists several concrete capabilities — 'the normalized event schema, the full event type list, idempotency via the event id field, and the correct handling for CANCELLATION versus EXPIRATION versus RENEWAL' — which matches the 'several specific actions; minor gaps' anchor. It falls short of 5 because signature verification, a core part of webhook consumption covered in the body, is not mentioned.

4 / 5

Completeness

Explicitly answers both questions: 'Use this skill when consuming RevenueCat webhooks on your backend' gives the when, and 'Covers the normalized event schema, the full event type list, idempotency via the event id field...' gives the what, matching the top anchor's structure.

5 / 5

Trigger Term Quality

Natural trigger phrases are comprehensively covered for this domain: 'RevenueCat webhooks', 'backend', 'cancellation', 'expiration', 'renewal', 'idempotency', 'event id' — exactly the vocabulary a developer needing this skill would use, with no obvious synonyms missing.

5 / 5

Distinctiveness Conflict Risk

The description is tightly niched to RevenueCat webhook consumption with distinct triggers (specific event type names, event id idempotency); there is virtually no overlap risk with other skills.

5 / 5

Total

19

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
RevenueCat/ai-toolkit
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.