CtrlK
BlogDocsLog inGet started
Tessl Logo

claude-managed-agents-webhooks

Receive and verify Anthropic Claude Managed Agents (CMA) webhooks. Use when setting up Claude Managed Agents webhook handlers, debugging signature verification, or handling agent session and vault events like session.status_idled, session.status_terminated, session.thread_created, vault.created, or vault_credential.refresh_failed.

69

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

81%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong, immediately usable skill: complete verified handlers in two languages with correct Standard Webhooks details and a well-organized reference bundle. The main costs are padded cross-promotion sections that dilute the token budget and three dead examples/ links that break navigation, plus partial duplication of the reference material inline.

Suggestions

Remove or drastically trim the 'Related Skills' section (10 external links) and fold the 'Recommended: webhook-handler-patterns' links into the Reference Materials section — they consume context without aiding the task.

Fix or remove the broken examples/express/, examples/nextjs/, and examples/fastapi/ links, since those paths do not exist in the skill bundle and will fail when followed.

Trim the in-body event tables to the few most common event types and point to references/overview.md for the full list, since that file already claims to carry the complete event reference.

DimensionReasoningScore

Conciseness

The core is dense and information-rich (raw-body capture, signed-content format, data.type vs top-level type), but the 'When to Use This Skill' section duplicates the frontmatter description, and the 'Related Skills' link farm (10 external links), 'Recommended' section, and 'Attribution' add no operational value and could be trimmed.

3 / 5

Actionability

Two fully executable handlers (Express and FastAPI) with signature verification, replay window, timing-safe comparison, raw-body middleware, and event dispatch are copy-paste ready, plus a concrete SDK alternative, env vars, and a runnable tunnel command. The only gap is the FastAPI handler's '# Handle event.data.type ...' placeholder, but the dispatch pattern is fully shown in the Express version.

5 / 5

Workflow Clarity

The single task (implement a verified webhook handler) is unambiguous: verify signature with timestamp window → reject with 400 → parse → dispatch → 200, with the validation checkpoint embedded in both implementations and the verify-first ordering stated in prose. Idempotency/retry semantics are explicitly deferred to the webhook-handler-patterns skill with pointed links.

5 / 5

Progressive Disclosure

Three real, clearly annotated one-level-deep references (overview.md, setup.md, verification.md) with good overview structure. However, the 'For complete working examples' links point to examples/express/, examples/nextjs/, and examples/fastapi/ which do not exist in the bundle, and the body's event tables duplicate the 'full event list' that references/overview.md already provides.

4 / 5

Total

17

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description in third person that states concrete capabilities and an explicit 'Use when...' clause with real trigger phrases and specific event names. It is clearly distinguishable via the CMA-specific framing, with only minor keyword gaps and slight overlap risk against sibling webhook skills.

DimensionReasoningScore

Specificity

Multiple concrete actions are explicitly stated — 'Receive and verify... webhooks', 'setting up... webhook handlers, debugging signature verification, handling agent session and vault events' — each grounded with concrete event names (session.status_idled, vault_credential.refresh_failed). Coverage spans setup, debugging, and event handling; third-person voice is used correctly.

5 / 5

Completeness

Explicitly answers both: what ('Receive and verify Anthropic Claude Managed Agents (CMA) webhooks') and when ('Use when setting up... handlers, debugging signature verification, or handling... events'), with concrete trigger phrases that mirror the good-example pattern.

5 / 5

Trigger Term Quality

Good natural terms users would say: 'webhook handlers', 'signature verification', 'session events', 'vault events', plus concrete event-type keywords. A few natural variations are missing (e.g., 'endpoint', 'HMAC', 'notifications'), keeping it just below the comprehensive-with-synonyms anchor.

4 / 5

Distinctiveness Conflict Risk

The niche is clearly anchored on 'Anthropic Claude Managed Agents (CMA)' with distinctive event-type triggers, so conflict risk is low. Minor overlap remains: 'debugging signature verification' and 'webhook handlers' could also match sibling webhook skills (stripe-webhooks, openai-webhooks, webhook-handler-patterns) in the same family.

4 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.