CtrlK
BlogDocsLog inGet started
Tessl Logo

bridge-xyz-webhooks

Receive and verify Bridge (bridge.xyz) webhooks. Use when setting up Bridge webhook handlers, debugging RSA signature verification of the X-Webhook-Signature header, or handling stablecoin/fiat events like customer.updated, kyc_link.updated, transfer.updated, and virtual_account.activity.

73

Quality

92%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-built skill body: executable, quirk-aware verification code with explicit validation and failure handling, lean event documentation, and clean one-level-deep reference structure. The weaknesses are minor — three dangling examples/ links and a somewhat promotional Related Skills section.

DimensionReasoningScore

Conciseness

The core is lean — a compact executable verify function with purposeful comments, a dense event table, and an exact env-var snippet — with no explanation of concepts Claude already knows. Minor over-trimming candidates: the 7-entry 'Related Skills' list (one promotional) and the attribution block. Not 5 because those sections add tokens that don't serve the task; not 3 because padding is minor, not 'some unnecessary explanation'.

4 / 5

Actionability

The verifyBridgeSignature function is complete and copy-paste executable (header parsing with base64-padding-safe splitting, replay tolerance, the double-hash quirk, try/catch, failure semantics 'Return a non-2xx (400)'), plus an exact env-var format and a runnable tunnel command. Not 4 because the common case is fully covered with no missing key details.

5 / 5

Workflow Clarity

The verification sequence has explicit validation checkpoints (timestamp replay guard, signature verify in try/catch) and an explicit error-recovery feedback loop ('Return a non-2xx (400) on failure so Bridge retries'), with the full setup flow one reference away. Not 4 because validation and failure handling are explicit, matching the anchor-5 pattern of validate → act → handle failure.

5 / 5

Progressive Disclosure

Good structure: core verification inline, three real one-level-deep references (overview.md, setup.md, verification.md) each signaled with a description, and details correctly split out. However, the body links examples/express/, examples/nextjs/, and examples/fastapi/ which do not exist in the bundle — dangling references. Not 5 because of those broken example links; not 3 because content placement and reference signaling are otherwise excellent.

4 / 5

Total

18

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person, concise, with an explicit 'Use when...' clause covering setup, debugging, and event handling, plus provider-specific trigger terms including concrete event names. The only gap is that webhook endpoint creation via the API is not named among the capabilities.

DimensionReasoningScore

Specificity

Explicit concrete actions — 'Receive and verify', 'setting up Bridge webhook handlers', 'debugging RSA signature verification of the X-Webhook-Signature header', 'handling stablecoin/fiat events' — but webhook endpoint creation/enabling via the API (a use case the body covers) is not named, so coverage has minor gaps. Not 5 because the anchor-5 example enumerates the full action surface; not 3 because several specific actions are listed beyond just naming the domain.

4 / 5

Completeness

Clearly answers both: what ('Receive and verify Bridge (bridge.xyz) webhooks') and when ('Use when setting up..., debugging..., or handling...') with concrete trigger phrases. Not 4 because the 'when' clause is fully explicit and specific, matching the anchor-5 example structure.

5 / 5

Trigger Term Quality

Comprehensive natural terms including brand synonyms ('Bridge', 'bridge.xyz'), 'webhook', 'X-Webhook-Signature', 'RSA signature verification', and four concrete event names (customer.updated, kyc_link.updated, transfer.updated, virtual_account.activity) users would actually mention. Not 4 because no common variation is missing.

5 / 5

Distinctiveness Conflict Risk

Clear niche — Bridge (bridge.xyz) webhooks specifically — with distinct branded triggers (X-Webhook-Signature, Bridge event names) that no sibling webhook skill (Stripe, PayPal, etc.) would match. Not 4 because overlap risk is minimal given the provider-specific qualifier throughout.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.