Receive and verify CircleCI outbound webhooks. Use when setting up a CircleCI webhook handler, debugging `circleci-signature` verification, or handling the `workflow-completed` and `job-completed` events CircleCI sends when a workflow or job reaches a terminal state. CircleCI signs the raw body with HMAC-SHA256 and sends a hex digest in a comma-separated versioned list (`v1=<hex>`) — only the latest version (`v1`) should ever be checked. Not Circle (circle.com, USDC/Circle Mint, ECDSA `X-Circle-Signature`) — unrelated company. Not CircleCI custom webhooks, which are inbound pipeline triggers going the other direction.
72
91%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
Passed
No findings from the security scan
This skill hasn't been evaluated yet
1b5cbf0
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.