CtrlK
BlogDocsLog inGet started
Tessl Logo

aws-sns-webhooks

Receive and verify AWS SNS (Amazon Simple Notification Service) webhooks over HTTP/HTTPS. Use when setting up an SNS HTTP subscription endpoint, confirming a subscription (SubscriptionConfirmation / SubscribeURL), verifying SNS message signatures (SigningCertURL, SignatureVersion 1 SHA1 / 2 SHA256), or handling Notification and UnsubscribeConfirmation messages.

72

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, mostly lean body that distinguishes SNS from HMAC webhooks, gives executable Node code and concrete commands, and progressively discloses detail into three real reference files. The Python manual-verification path and absence of an explicit numbered validation checklist keep actionability and workflow clarity just below the top anchor.

Suggestions

Add a short numbered handler workflow (read header → verify signature → confirm subscription if needed → process) with an explicit validation checkpoint so the sequence is scannable rather than spread across sections.

Include a minimal complete Python canonical-string + RSA-verify snippet inline, or clearly mark the reference file as containing copy-paste-ready code, to close the actionability gap on the manual path.

Tighten the 'How SNS Delivery Differs From HMAC Webhooks' bullets to the strictly non-obvious points to recover a few tokens.

DimensionReasoningScore

Conciseness

Efficient and largely assumes Claude's competence; the 'How SNS Delivery Differs From HMAC Webhooks' section earns its place as genuinely non-obvious. A few explanatory sentences could be trimmed without losing clarity.

4 / 5

Actionability

Provides executable Node code, concrete commands (npx hookdeck-cli), an env var example, and a message-type table; the Python manual-verify path is described in prose and deferred to a reference file rather than shown as complete inline code, a minor gap.

4 / 5

Workflow Clarity

The handler sequence (read x-amz-sns-message-type header, verify signature, confirm handshake via SubscribeURL, then process) is clear across sections, with the signature check acting as validation. It is not presented as a numbered checklist with explicit validation checkpoints, so it falls just short of anchor 5.

4 / 5

Progressive Disclosure

Clear overview with well-signaled, one-level-deep references to three real reference files (overview.md, setup.md, verification.md) and a clean section structure; content is appropriately split and easy to navigate.

5 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description that clearly states capabilities and provides explicit 'Use when' trigger guidance covering subscription confirmation, signature verification, and message handling. It is distinct from sibling HMAC webhook skills and free of vague fluff.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'Receive and verify', 'setting up an SNS HTTP subscription endpoint', 'confirming a subscription', 'verifying SNS message signatures', 'handling Notification and UnsubscribeConfirmation messages' — with comprehensive coverage of the skill's capabilities.

5 / 5

Completeness

Explicitly answers both 'what' ('Receive and verify AWS SNS webhooks over HTTP/HTTPS') and 'when' via an explicit 'Use when...' clause listing concrete trigger scenarios, matching the anchor-5 example structure.

5 / 5

Trigger Term Quality

Comprehensive natural and technical trigger terms users would actually say — 'AWS SNS', 'webhooks', 'SubscriptionConfirmation', 'SubscribeURL', 'SigningCertURL', 'SignatureVersion', 'Notification', 'UnsubscribeConfirmation' — including the specific envelope field names.

5 / 5

Distinctiveness Conflict Risk

AWS SNS (RSA/certificate-based signature verification) is a clearly distinct niche from HMAC shared-secret webhook skills like Stripe, Shopify, and GitHub, with minimal conflict risk.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.