CtrlK
BlogDocsLog inGet started
Tessl Logo

bitbucket-webhooks

Receive and verify Bitbucket Cloud webhooks. Use when setting up Bitbucket webhook handlers, debugging X-Hub-Signature verification, or handling repository and pull request events like repo:push, pullrequest:created, pullrequest:updated, pullrequest:fulfilled, or pullrequest:rejected.

69

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A lean, highly actionable reference skill: complete dual-language verification code, useful tables, and real bundle references. Main weaknesses are dead examples/ links in the bundle, an inline promo for a separate skill, and the absence of an explicitly sequenced handler workflow with validation checkpoints.

Suggestions

Either include the examples/express, examples/nextjs, and examples/fastapi directories in the bundle or remove/repoint those links, since they currently resolve to nothing.

Trim the Attribution and Related Skills sections (or move them to a single reference file) to cut non-operational tokens.

Add a short numbered handler sequence inline (receive raw body -> verify signature -> check X-Event-Key -> dispatch idempotently) with an explicit validation checkpoint, rather than delegating it to an external skill's docs.

DimensionReasoningScore

Conciseness

The body is dense and useful — two tight code samples, compact tables, and no explanation of concepts Claude already knows. However, the 'Attribution' section and the 7-item 'Related Skills' list are promotional overhead that earns no operational value, keeping it just below the 'every token earns its place' 5 anchor.

4 / 5

Actionability

Both verification functions are complete, executable, copy-paste ready (including edge-case handling such as the missing-signature and timingSafeEqual-throw paths), and are backed by a concrete env var and a runnable tunnel command ('npx hookdeck-cli listen 3000 bitbucket --path /webhooks/bitbucket'). This matches the 'fully executable, covers common cases' 5 anchor.

5 / 5

Workflow Clarity

The core action (verify the raw body timing-safely before anything else) is unambiguous and the handler sequence is explicitly signaled via the pointer 'Verify first, parse second, handle idempotently third'. The multi-step setup flow (create webhook, set secret, wire route) is delegated to references/setup.md rather than sequenced inline, and there is no inline validation checkpoint beyond the verify function itself — a minor gap versus the 5 anchor's explicit feedback loops.

4 / 5

Progressive Disclosure

Good structure: three one-level-deep, well-signaled reference files (references/overview.md, setup.md, verification.md) that all exist in the bundle, each with a one-line description. However, the body links to examples/express/, examples/nextjs/, and examples/fastapi/ which do not exist in the bundle, and the 'Recommended' section links four files inside a different skill's GitHub tree — dead or out-of-bundle references that keep it below the 5 anchor's 'easy navigation'.

4 / 5

Total

17

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with an explicit 'Use when...' clause, concrete actions, provider-specific trigger terms, and a clearly delineated niche. The only room for improvement is slightly broader keyword coverage (synonyms like 'webhook secret' or 'payload').

Suggestions

Add a few natural synonyms such as 'webhook secret' or 'event payloads' to broaden trigger-term coverage.

Mention responding to or acknowledging deliveries (e.g. returning 2xx) to round out the capability list.

DimensionReasoningScore

Specificity

"Receive and verify Bitbucket Cloud webhooks" plus "debugging X-Hub-Signature verification" and "handling repository and pull request events like repo:push, pullrequest:created..." names several specific concrete actions with only minor coverage gaps (no mention of responding/acknowledging deliveries). It lists more than 1-2 actions but stops short of the comprehensive 5 anchor.

4 / 5

Completeness

It explicitly answers 'what' ("Receive and verify Bitbucket Cloud webhooks") and 'when' with a concrete "Use when setting up... debugging... or handling..." clause listing specific triggers. This matches the 5 anchor (clear what AND when with concrete trigger phrases); the 4 anchor requires a weaker or less specific 'when', which does not apply here.

5 / 5

Trigger Term Quality

Natural phrases users would say are present: "Bitbucket webhook handlers", "signature verification", "X-Hub-Signature", and concrete event keys like "repo:push" and "pullrequest:created". A few common variations (e.g. "webhook secret", "payload", "Bitbucket Cloud API") are missing, so it fits 'good keyword coverage; a few natural terms missing' rather than the fully comprehensive 5 anchor.

4 / 5

Distinctiveness Conflict Risk

"Bitbucket Cloud webhooks" with Bitbucket-specific headers and event keys is a clear niche, distinct from GitHub/GitLab/Stripe webhook skills, with minimal risk of triggering for the wrong skill. It clearly matches the 5 anchor; it is not merely 'mostly distinct' as in the 4 anchor.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.