CtrlK
BlogDocsLog inGet started
Tessl Logo

azure-event-grid-webhooks

Receive and validate Azure Event Grid webhook deliveries. Use when setting up an Event Grid WebHook event handler, implementing the Microsoft.EventGrid.SubscriptionValidationEvent handshake (echo data.validationCode as validationResponse with HTTP 200), implementing the CloudEvents v1.0 HTTP OPTIONS abuse-protection preflight (WebHook-Request-Origin / WebHook-Allowed-Origin), checking the aeg-subscription-name / aeg-event-type / aeg-delivery-count headers, authenticating deliveries with a static delivery-property header or a Microsoft Entra ID bearer token, parsing Event Grid schema arrays vs CloudEvents objects, or handling events like Microsoft.Storage.BlobCreated. Event Grid does NOT sign the request body — there is no HMAC signature.

74

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

92%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An action-dense, well-structured body with executable code, explicit validation checkpoints, and clean one-level-deep references. The only friction is repeated re-emphasis of the no-signature point across sections.

DimensionReasoningScore

Conciseness

Dense and mostly lean — no padding about what webhooks are, with concrete code and tables earning their tokens — but the 'no signature / no HMAC' point is restated across four sections, which could be tightened.

4 / 5

Actionability

Copy-paste-ready JavaScript handlers, Azure CLI commands, env-var blocks, and constant-time comparison helpers cover the common cases fully and are executable as written.

5 / 5

Workflow Clarity

The two handshakes and three auth modes are clearly sequenced with explicit validation checkpoints (fail-closed, 403 on unknown subscription, dedupe on event id) and a feedback loop for the AwaitingManualAction -> validationUrl recovery path.

5 / 5

Progressive Disclosure

SKILL.md is a well-structured overview pointing one level deep to real, clearly signaled references (overview.md, setup.md, verification.md, all present in the bundle), with detailed material appropriately split out.

5 / 5

Total

19

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A precise, action-dense description that clearly answers both what and when, and carves out a distinct niche with an explicit anti-HMAC boundary. Slightly heavy on technical jargon over natural phrasing, but trigger coverage is thorough.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — handshake echo, CloudEvents OPTIONS preflight, header checks, three auth modes, schema parsing — with comprehensive coverage of the skill's surface area.

5 / 5

Completeness

Explicitly states what ('Receive and validate Azure Event Grid webhook deliveries') and when ('Use when setting up... implementing... or handling events like Microsoft.Storage.BlobCreated') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Strong natural terms ('Azure Event Grid webhook', 'Event Grid WebHook event handler', event types, header names) but the phrasing leans technical and dense rather than covering conversational synonyms a user might actually say.

4 / 5

Distinctiveness Conflict Risk

Narrow Azure Event Grid niche with a distinguishing negation ('does NOT sign the request body — there is no HMAC signature') that separates it from Stripe/Shopify-style signers, minimizing wrong-skill triggering.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.