CtrlK
BlogDocsLog inGet started
Tessl Logo

aftership-webhooks

Receive and verify AfterShip webhooks. Use when setting up AfterShip webhook handlers, debugging AfterShip signature verification (aftership-hmac-sha256, as-signature-hmac-sha256, am-webhook-signature), or handling AfterShip Tracking events like tracking_update, edd_revise and tracking_pending_time, AfterShip Returns events like return.approved, AfterShip Warranty events like warranty.created, and AfterShip Shipping (Postmen) events like create_a_label.

73

Quality

92%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong, high-signal body: the verification section delivers complete executable code with the exact non-obvious details (header variants, prefix, raw body, per-product secrets), and detail is correctly pushed into three well-organized reference files. The main deductions are the cross-promotional Related Skills/Attribution sections and dangling example-directory links.

Suggestions

Trim the 11-link "Related Skills" section to the 2-3 most relevant siblings (e.g., webhook-handler-patterns and one comparable provider skill) and drop or compress the Attribution boilerplate to save ~30 lines of tokens.

Fix the dangling examples/express/, examples/nextjs/, and examples/fastapi/ links — either include those directories in the bundle or remove/replace the pointer so navigation stays one level deep and every referenced path resolves.

Replace the version-pinned aside ("@aftership/tracking-sdk 17.0.0 has no webhook-verification helper") with a version-agnostic statement so the guidance does not age.

DimensionReasoningScore

Conciseness

Core sections are dense and information-rich — every fact is non-obvious (three header variants, prefix stripping, secret-as-UTF-8, no timestamp/replay window, the 14-retry schedule). However, ~40 lines of "Related Skills" cross-promotion (11 sibling links), the Attribution boilerplate, and the version-specific aside ("@aftership/tracking-sdk 17.0.0") are minor trimmable padding, which fits the 4 anchor rather than 5.

4 / 5

Actionability

Fully executable, copy-paste-ready code in both Node and Python (fail-closed, timing-safe, header-order handling), plus the exact hookdeck-cli tunnel command, env var, port constraints, and retry math — concrete guidance covering the common cases end to end.

5 / 5

Workflow Clarity

Verify-first ordering is explicit ("Verify first, parse second, handle idempotently third"), the code fails closed, and gotchas (raw body, per-product secrets, respond 2xx) are flagged as checkpoints. It falls short of 5 because the overall flow (tunnel → register endpoint → verify → respond) is organized by topic rather than an explicit ordered sequence with feedback loops.

4 / 5

Progressive Disclosure

A clear overview with well-signaled, one-level-deep references: the Reference Materials section names each of the three real bundle files (overview.md, setup.md, verification.md) with its purpose, and they exist and match. Not 5: the examples/express/, examples/nextjs/, and examples/fastapi/ links point at directories absent from the bundle, and four companion-skill references are external GitHub URLs — minor navigation gaps.

4 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: third-person, concise, and fully explicit about what the skill does and when to use it, with exhaustive AfterShip-specific trigger tokens including all three signature header names and representative event codes for each product. No fluff, no over-claims, minimal conflict risk with sibling skills.

DimensionReasoningScore

Specificity

"Receive and verify AfterShip webhooks", "debugging AfterShip signature verification", and "handling... events" name multiple concrete actions, and the description enumerates the exact header names (aftership-hmac-sha256, as-signature-hmac-sha256, am-webhook-signature) and event codes (tracking_update, return.approved, warranty.created, create_a_label) across all four products — comprehensive coverage with no gaps for this domain.

5 / 5

Completeness

It explicitly answers both: "what" (receive and verify AfterShip webhooks) and "when" ("Use when setting up... debugging... or handling...") with concrete trigger scenarios, matching the anchor-5 pattern of a clear what plus an explicit, specific when.

5 / 5

Trigger Term Quality

It captures the natural phrases a user would say ("setting up AfterShip webhook handlers", "debugging AfterShip signature verification", "handling AfterShip Tracking events") plus synonyms like "Shipping (Postmen)" and exact technical tokens, giving comprehensive keyword coverage including variations.

5 / 5

Distinctiveness Conflict Risk

Every trigger term is AfterShip-branded (product names, header names, event codes), so it occupies a clear niche and would not fire for sibling webhook skills like shipstation-webhooks or shopify-webhooks.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.