CtrlK
BlogDocsLog inGet started
Tessl Logo

auth0-webhooks

Receive and verify Auth0 webhooks delivered via Custom Log Streams (HTTP). Use when setting up an Auth0 log stream HTTP endpoint, validating the configured Authorization token, or handling batched authentication log events like s (success login), f (failed login), ss (signup), and sepft (password-grant token exchange).

68

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Well-structured, actionable content with executable verification code and a clean overview-to-references split. The main gaps are the dangling examples/ directories referenced for complete handlers, an implicit (unnumbered) workflow sequence, and some token spend on cross-promotional sections.

Suggestions

Ship the examples/ directories (express, nextjs, fastapi) in the bundle or replace those links with a single inline minimal-handler snippet, so the 'complete handlers' promise does not dangle.

Make the core sequence explicit and numbered (1. timing-safe verify Authorization header, 2. parse JSON array, 3. return 2xx immediately, 4. process events asynchronously) and add a short note on handling malformed batches.

Trim the 'When to Use This Skill' question list and the 'Related Skills' section (7 links) to reduce token overhead that duplicates the frontmatter description and adds cross-promotion.

DimensionReasoningScore

Conciseness

The body is efficient — a tight verification snippet, a compact event-code table, env var, and a tunnel command — with no explanation of concepts Claude already knows. Minor over-length comes from the "When to Use" question list (duplicates the description) and the promotional "Related Skills"/"Recommended" sections, so it fits the 4 anchor (efficient, minor trimming possible) rather than the 5 anchor where every token earns its place.

4 / 5

Actionability

The timing-safe token comparison code is complete and executable, and the env var and hookdeck tunnel commands are copy-paste ready. However, the pointer to "complete handlers" (examples/express/, examples/nextjs/, examples/fastapi/) references directories that are not present in the bundle, leaving the handler-implementation step without concrete material — a minor gap consistent with anchor 4 rather than fully executable coverage at 5.

4 / 5

Workflow Clarity

The sequence — configure the stream, timing-safe verify the Authorization header on every request, parse the JSON array, return 2xx quickly, do slow work asynchronously — is clear and includes an explicit verification step with the retry consequence stated ("Auth0 retries on any non-2xx"). It falls short of anchor 5 because the steps are implicit rather than explicitly sequenced, and there is no inline error-recovery loop for malformed payloads; it is above anchor 3 since validation for the risky part (auth) is explicitly present.

4 / 5

Progressive Disclosure

SKILL.md acts as a genuine overview, with three real one-level-deep reference files (references/overview.md, setup.md, verification.md) clearly listed with descriptions, all of which exist in the bundle. It misses anchor 5 because the in-body examples/express/, examples/nextjs/, and examples/fastapi/ links dangle (no such directories in the bundle), a minor navigation gap under the actual bundle structure.

4 / 5

Total

16

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete capabilities, an explicit "Use when" clause with multiple triggers, and a clearly bounded Auth0 niche. The only weakness is slightly incomplete synonym coverage for natural trigger terms.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions — "Receive and verify Auth0 webhooks", "setting up an Auth0 log stream HTTP endpoint", "validating the configured Authorization token", "handling batched authentication log events" — and grounds them with real event codes (s, f, ss, sepft). Coverage is comprehensive for this domain rather than just several actions with minor gaps, so it matches the 5 anchor.

5 / 5

Completeness

It explicitly answers both questions: the "what" ("Receive and verify Auth0 webhooks delivered via Custom Log Streams (HTTP)") and a concrete "Use when" clause with three specific triggers. This matches the 5 anchor's pattern of concrete trigger phrases attached to a clear capability statement.

5 / 5

Trigger Term Quality

Good keyword coverage with natural phrases users would say ("Auth0 webhooks", "log stream HTTP endpoint", "Authorization token", "batched authentication log events"), but common variations such as "Auth0 logs", "login events", or "activity log" are missing. It sits between anchor 3 (missing common variations) and anchor 5 (comprehensive synonyms), noticeably above the midpoint.

4 / 5

Distinctiveness Conflict Risk

The description is firmly scoped to Auth0 Custom Log Streams with Auth0-specific terminology, creating a clear niche with minimal overlap risk against generic webhook skills or sibling provider skills (Clerk, FusionAuth, Stripe). It clearly matches the 5 anchor.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.