CtrlK
BlogDocsLog inGet started
Tessl Logo

clio-webhooks

Receive and verify Clio (Clio Manage) webhooks. Use when setting up Clio webhook handlers, debugging X-Hook-Signature verification, completing the X-Hook-Secret handshake, or handling legal practice events like matter.created, contact.updated, activity.created, or bill events.

66

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body delivers genuinely valuable provider-specific knowledge (encoding ambiguity resolved from a live delivery, handshake quirks, expiration rules) with copy-paste verification code in two languages. Its weaknesses are repetition of the hex/base64 caveat, incomplete handshake/renewal code, and references to example directories that are absent from the bundle.

Suggestions

State the hex-vs-base64 finding once in the Verification prose and drop the duplicate code comments in both handlers and the restatement in the Important Headers table.

Replace the commented-out handshake snippet with an executable echo example (and add a concrete PATCH expires_at example for renewal), since the examples/ directories that would have shown this do not exist in the bundle.

Remove or restore the examples/express/, examples/nextjs/, and examples/fastapi/ links — they are dead paths — and trim the models/event table that duplicates references/overview.md.

DimensionReasoningScore

Conciseness

The content is substantive and free of concept-teaching padding, but the hex-vs-base64 caveat is repeated four times (prose explanation, two inline code comments, and the headers table), and the EU auto-enable digression ("though in one observed EU test the webhook auto-enabled...") is an aside that could be trimmed to the reference file. This matches 'mostly efficient but... could be tightened' rather than the 'minor instances' of level 4.

3 / 5

Actionability

The core verification logic is fully executable in both Node and Python (timing-safe compare, length-mismatch handling), plus a concrete webhook-creation curl command and tunnel command. However, the handshake echo is only a commented-out one-liner (line 101), the 'complete handlers' it delegates to (examples/express/, examples/nextjs/, examples/fastapi/) do not exist in the bundle, and the expiry-renewal PATCH has no example — gaps slightly beyond level 5's 'specific examples cover the common cases'.

4 / 5

Workflow Clarity

The handshake-before-verification ordering is explicit ("Handle the handshake **before** signature verification"), the secret's capture and storage are explained ("Save it... keyed by webhook_id"), and expiration renewal is flagged with its mechanism ("renew before expiry by updating expires_at (PATCH...)"). It lacks a consolidated ordered sequence and an error-recovery loop for failed verification (delegated to references), fitting 'clear sequence with most checkpoints present; minor validation gaps'.

4 / 5

Progressive Disclosure

The three real bundle files (references/overview.md, setup.md, verification.md) are one level deep and clearly signaled with one-line descriptions in a Reference Materials section, and setup.md is also linked contextually. But the body's pointers to examples/express/, examples/nextjs/, and examples/fastapi/ are dead (those directories don't exist), and the event table/models list duplicates material that references/overview.md covers — 'good structure... minor organization gaps' rather than level 5's easy navigation.

4 / 5

Total

15

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it states concrete capabilities in third person, includes an explicit 'Use when' clause with specific trigger scenarios, and is tightly scoped to Clio so it won't collide with sibling webhook skills. The only gap is a couple of missing natural trigger terms, most notably X-Hook-Secret (the actual handshake header) and webhook expiration/renewal.

DimensionReasoningScore

Specificity

Multiple concrete actions are enumerated with specific technical identifiers: "Receive and verify Clio (Clio Manage) webhooks", "setting up Clio webhook handlers", "debugging X-Hook-Signature verification", "completing the...handshake", and named events like "matter.created, contact.updated, activity.created, or bill events". This comprehensively covers the skill's capability surface, matching the anchor for multiple specific concrete actions rather than the 'minor gaps' of the level below.

5 / 5

Completeness

Clearly answers both: what ("Receive and verify Clio (Clio Manage) webhooks") and when via an explicit "Use when setting up... debugging... completing... or handling..." clause with concrete trigger phrases. Third-person voice is used throughout, and the 'Use when' cap does not apply.

5 / 5

Trigger Term Quality

Good natural keyword coverage ("Clio webhooks", "webhook handlers", "X-Hook-Signature", "matter.created", "bill events", "legal practice events"), but a few natural terms are missing: "X-Hook-Secret" (the actual handshake header a user debugging activation would say — the description instead says "X-Hook-Signature handshake") and webhook expiration/renewal triggers, which the body marks as important. Fits 'good keyword coverage; a few natural terms missing' rather than the comprehensive synonym coverage of 5.

4 / 5

Distinctiveness Conflict Risk

Every trigger is anchored to the specific product ("Clio (Clio Manage)", "legal practice events", Clio-specific event names), giving it a clear niche with minimal conflict risk. The only theoretical overlap is with asana-webhooks on the shared "X-Hook-Signature" header term, but the Clio branding dominates and would not mis-trigger.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.