CtrlK
BlogDocsLog inGet started
Tessl Logo

calendly-webhooks

Receive and verify Calendly webhooks. Use when setting up Calendly webhook handlers, debugging Calendly signature verification, or handling scheduling events like invitee.created, invitee.canceled, invitee_no_show.created, or routing_form_submission.created.

69

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-built skill body: executable verification code with security details, a clean event table, and properly structured one-level references. The main deductions are dangling examples/ paths and roughly a quarter of the body spent on attribution and cross-promotional link sections rather than instruction.

Suggestions

Fix or remove the examples/express/, examples/nextjs/, and examples/fastapi/ links — these directories are absent from the bundle, so the "complete handlers with route wiring, event dispatch, and tests" promise is currently unfulfillable (progressive_disclosure).

Trim the Attribution block and the 7-entry Related Skills list to one line each (conciseness) — they consume ~25 lines of context with no instructional value.

Add a short numbered end-to-end sequence (create subscription → configure tunnel → verify → dispatch) in the body so the workflow is explicit rather than spread across sections and external files (workflow_clarity).

DimensionReasoningScore

Conciseness

The instructional core is lean and dense: the verification section gets straight to the signed-content format, tolerance, and raw-body gotcha, and the events table and env-var/tunnel snippets are minimal. Minor trimmable padding exists in the Attribution block and the cross-promotional "Related Skills" list (7 external links) plus the "Recommended" section, which earn no instructional value.

4 / 5

Actionability

Fully executable, copy-paste-ready Node.js verification function including header parsing, replay-tolerance check, HMAC computation, and timing-safe comparison with a length-mismatch guard; complemented by a concrete env var, a runnable tunnel command, and a real event table.

5 / 5

Workflow Clarity

The core verify flow is unambiguous with built-in checkpoints (stale-timestamp rejection, malformed-signature return false), and pointer text establishes verify → parse → handle order. It falls short of the 5 anchor because no explicit end-to-end sequence (subscription setup → receive → verify → dispatch) appears in the body itself; each stage lives in a different section or external file.

4 / 5

Progressive Disclosure

Good structure: SKILL.md is an overview with clearly labeled, one-level-deep references (overview/setup/verification, all present in the bundle and described in "Reference Materials"). The gap versus the 5 anchor is that the prominent "examples/express/", "examples/nextjs/", and "examples/fastapi/" links point to paths that do not exist in this bundle, breaking navigation for the promised complete handlers.

4 / 5

Total

17

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person, concrete actions, an explicit "Use when" clause with multiple trigger scenarios, and provider-specific event names that make it highly distinguishable. Only minor gains available from broader synonym coverage.

DimensionReasoningScore

Specificity

Concrete actions are named — "Receive and verify Calendly webhooks", "setting up Calendly webhook handlers", "debugging Calendly signature verification", "handling scheduling events" — with specific event names listed. Falls just short of the 5 anchor because coverage is confined to receive/verify/handle and omits adjacent concrete capabilities (e.g., replay-protection tuning or subscription management).

4 / 5

Completeness

Explicitly answers both what ("Receive and verify Calendly webhooks", handle the listed scheduling events) and when ("Use when setting up Calendly webhook handlers, debugging Calendly signature verification, or handling scheduling events like...") with concrete trigger phrases, matching the 5 anchor; voice is third person.

5 / 5

Trigger Term Quality

Good natural keyword coverage: "Calendly webhooks", "webhook handlers", "signature verification", "scheduling events", plus concrete event names (invitee.created, invitee.canceled, routing_form_submission.created) a debugging user would actually type. A few natural variants (e.g., "webhook signature", "endpoint", "no-show") are partially covered but not exhaustive, matching the 4 rather than 5 anchor.

4 / 5

Distinctiveness Conflict Risk

"Calendly" and its proprietary event names (invitee_no_show.created, routing_form_submission.created) form a clear niche distinct from sibling webhook skills (Stripe, Shopify, GitHub), with minimal risk of triggering for the wrong provider.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.