CtrlK
BlogDocsLog inGet started
Tessl Logo

bigcommerce-webhooks

Receive and verify BigCommerce webhooks. Use when setting up BigCommerce webhook handlers, debugging Standard Webhooks signature verification, or handling store events like store/order/created, store/order/statusUpdated, store/product/updated, or store/cart/abandoned.

69

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, high-signal body that delivers executable verification code and the provider-specific facts Claude would not know. Weak points are minor: no explicit step ordering for the handler workflow and several links (examples/*) that are dead relative to the bundle.

DimensionReasoningScore

Conciseness

Nearly every token carries non-obvious, provider-specific facts (thin payloads, ~48h retry then deactivation, the base64-encode-the-secret subtlety, raw-body requirement) with no padding about basics. Not a 5 because the "Recommended" and "Related Skills" sections (7+ external GitHub links) and the attribution block are cross-promotional bulk that could be trimmed.

4 / 5

Actionability

Copy-paste-ready Node and Python verification code with exact header names, an executable npx tunnel command, a curl hook-creation command, and concrete env-var declarations — the common cases are fully covered executably.

5 / 5

Workflow Clarity

A workable end-to-end path is present (create hook via API → verify with named headers → respond 200 immediately) with real checkpoints: "Log incoming headers on your first delivery to confirm", the custom-header fallback when signatures are absent, and the hook-activation delay note. Not a 5 because the receive→verify→parse→respond sequence is never explicitly ordered (delegated to an external skill) and the callback-to-fetch-full-resource step has no code.

4 / 5

Progressive Disclosure

Good structure: core verification essentials inline, three real one-level-deep reference files clearly listed with descriptions (all verified present in references/). Not a 5 because the body's links to examples/express/, examples/nextjs/, and examples/fastapi/ point to directories that do not exist in the bundle, and the "Recommended" section duplicates detail that belongs in a single pointer.

4 / 5

Total

17

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is well-constructed: a crisp two-part what/when structure with concrete trigger phrases and specific event scopes. It follows the third-person convention and avoids padding.

DimensionReasoningScore

Specificity

"Receive and verify BigCommerce webhooks" plus "setting up BigCommerce webhook handlers, debugging Standard Webhooks signature verification, or handling store events" names several concrete actions, with concrete scope strings (store/order/created, store/cart/abandoned). Not a 5 because capability coverage has a minor gap — e.g., creating hooks via the API is only weakly implied by "setting up handlers" rather than named.

4 / 5

Completeness

Explicitly answers both: what ("Receive and verify BigCommerce webhooks") and when ("Use when setting up... debugging... or handling store events like...") with concrete trigger phrases — a direct match for the anchor-5 example pattern.

5 / 5

Trigger Term Quality

Natural trigger phrases are strong: "webhooks", "webhook handlers", "signature verification", and exact event scopes a user would paste ("store/order/created", "statusUpdated"). Not a 5 because a few natural synonyms are missing (e.g., "HMAC", "callback", "endpoint", "client secret").

4 / 5

Distinctiveness Conflict Risk

"BigCommerce" pins a clear niche with distinct, provider-specific triggers (event scope strings, Standard Webhooks); only minimal overlap with sibling e-commerce webhook skills (Shopify/WooCommerce), which are themselves explicitly named providers.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.