CtrlK
BlogDocsLog inGet started
Tessl Logo

bridge-api-webhooks

Receive and verify Bridge API webhooks (bridgeapi.io — the open-banking aggregator by Bridge/Bankin', NOT bridge.xyz). Use when setting up Bridge API webhook handlers, debugging BridgeApi-Signature HMAC-SHA256 verification, or handling events like item.created, item.refreshed, item.account.updated, payment.transaction.created, or user.deleted.

72

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong, well-structured body: executable verification code in two languages, a complete event table, and genuinely non-obvious operational details (IP allowlist, response-size limit, retry behavior). The main weaknesses are minor — a disambiguation note redundant with the description and reference links (examples/*) that are absent from the bundle.

Suggestions

Remove or trim the 'Which Bridge?' callout at the top of the body since the frontmatter description already performs the bridgeapi.io vs bridge.xyz disambiguation, saving context tokens.

Fix the examples/express/, examples/nextjs/, and examples/fastapi/ links — these paths are not present in the bundle, so either include the example directories or link to the canonical GitHub URLs.

Consider trimming the 'Related Skills' section to the 2-3 most relevant siblings (e.g., bridge-xyz-webhooks and webhook-handler-patterns) to reduce token cost while preserving navigation.

DimensionReasoningScore

Conciseness

The body is lean and carries provider-specific facts Claude cannot know (source IPs, 10 KB response limit, retry window, TEST_EVENT, 24h/2-secret rotation). Minor over-explanation exists — the top 'Which Bridge?' note duplicates the description's disambiguation, and the Related Skills list adds bulk — but nothing is padded enough to drop to anchor 3.

4 / 5

Actionability

Fully executable, copy-paste-ready guidance: complete Node and Python verification functions (including timing-safe comparison, v1-scheme filtering, and malformed-signature handling), the exact env var name, the exact tunnel command ('npx hookdeck-cli listen 3000 bridge-api --path /webhooks/bridge-api'), and a concrete payload example. Covers the common cases.

5 / 5

Workflow Clarity

The core verification flow is unambiguous with failure paths handled (try/catch, empty-signature rejection, rotation tolerance), and the verify-first ordering is stated ('Verify first, parse second, handle idempotently third'). The multi-step setup sequence exists but is delegated to references/setup.md rather than sequenced inline — a minor checkpoint gap that keeps this below anchor 5.

4 / 5

Progressive Disclosure

Good structure against the actual bundle: three one-level-deep, clearly labeled reference files (overview, setup, verification) listed in a 'Reference Materials' section with descriptions. The gap is that the inline links to examples/express/, examples/nextjs/, and examples/fastapi/ point to paths that do not exist in the local bundle, so navigation is not fully reliable — below anchor 5 but well above anchor 3.

4 / 5

Total

17

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A model description: precise domain identification with explicit disambiguation from the easily-confused bridge.xyz, concrete capabilities, natural trigger phrases including specific event names, and an explicit 'Use when' clause. It scores at or near the top on every dimension.

DimensionReasoningScore

Specificity

Names the domain precisely ('Bridge API webhooks (bridgeapi.io — the open-banking aggregator)') and concrete actions ('Receive and verify', 'debugging BridgeApi-Signature HMAC-SHA256 verification', 'handling events like item.created...'), with only minor gaps in coverage — not clearly below anchor 3's '1-2 concrete actions' nor fully at anchor 5's comprehensive multi-action coverage.

4 / 5

Completeness

Explicitly answers both: what ('Receive and verify Bridge API webhooks (bridgeapi.io — the open-banking aggregator by Bridge/Bankin', NOT bridge.xyz)') and when ('Use when setting up Bridge API webhook handlers, debugging BridgeApi-Signature HMAC-SHA256 verification, or handling events like...'). Matches the anchor-5 example structure of concrete what + explicit 'Use when' triggers.

5 / 5

Trigger Term Quality

Natural trigger phrases match what a user would actually say: 'webhook handlers', 'signature verification failing', 'signing-secret rotation', and concrete event names (item.refreshed, item.account.updated, payment.transaction.created, user.deleted), plus synonyms 'Bridge/Bankin', 'bridgeapi.io', 'open-banking aggregator'. Coverage of natural terms for this niche is comprehensive.

5 / 5

Distinctiveness Conflict Risk

Exceptionally distinct: names the exact domain (bridgeapi.io), the company (Bridge/Bankin'), and explicitly disambiguates the highest-confusion sibling ('NOT bridge.xyz'), eliminating the main collision risk. Clear niche with minimal conflict risk.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.