CtrlK
BlogDocsLog inGet started
Tessl Logo

cloudinary-webhooks

Receive and verify Cloudinary webhooks (notifications). Use when setting up a Cloudinary notification receiver, verifying the x-cld-signature and x-cld-timestamp headers with the official cloudinary SDK, debugging Cloudinary signature verification failures, or handling notification_type events like upload, eager, delete, rename, moderation, and resource_tags_changed.

73

Quality

92%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a well-structured, actionable overview: executable verification code with explicit error checkpoints, a compact event-type table, and clearly signaled one-level-deep references. The main deductions are dangling examples/ links that resolve to nothing in the bundle, trimmable cross-promotion sections, and the handling workflow being outsourced to external references.

Suggestions

Ship the examples/ directory (express, nextjs, fastapi) in the bundle or remove the 'For complete handlers with tests, see examples/...' pointer, since those paths currently resolve to nothing.

Trim the 7-item Related Skills list and the 4 external webhook-handler-patterns links to a single line each — they consume tokens without guiding the task at hand.

State the post-verification handling sequence inline (verify → parse → handle idempotently) in one or two lines instead of relying solely on the external webhook-handler-patterns skill.

DimensionReasoningScore

Conciseness

The core sections — verification code, env vars, the event-type table, and the tunnel command — are lean and assume competence, but the 7-item "Related Skills" list and the 4-link "Recommended" section are promotional cross-links that could be trimmed. Fits 'efficient; minor instances that could be trimmed' rather than the every-token-earns-its-place top anchor.

4 / 5

Actionability

Fully executable guidance: copy-paste SDK verification code with config, header extraction, and 400/401 error responses; exact environment variables; a concrete hookdeck CLI command with path; and a table of event types with notable fields. The raw-body gotcha is called out precisely where it matters.

5 / 5

Workflow Clarity

The verification sequence has explicit checkpoints (reject missing headers with 400 before 401, verify the raw body byte-for-byte, 401 on invalid), but the post-verification handling sequence (parse then handle idempotently) is only delegated to an external skill's references rather than stated inline. Clear sequence with a minor validation gap.

4 / 5

Progressive Disclosure

Good structure overall: a lean overview with three real, one-level-deep reference files clearly signaled both inline and in a Reference Materials section. However, the body points to examples/express/, examples/nextjs/, and examples/fastapi/ for complete tested handlers, and no examples/ directory exists in the bundle — a navigation dead-end that keeps this below the top anchor.

4 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is exemplary: it states concrete capabilities, includes natural trigger terms with synonyms, and pairs a clear what with an explicit Use-when clause covering setup, verification, debugging, and event handling. Third-person voice is used and there is no fluff.

DimensionReasoningScore

Specificity

Multiple specific concrete actions — "Receive and verify Cloudinary webhooks", "verifying the x-cld-signature and x-cld-timestamp headers with the official cloudinary SDK", "debugging Cloudinary signature verification failures", and handling a named list of notification_type events — give comprehensive coverage with no gaps, matching the top anchor.

5 / 5

Completeness

Explicitly answers both what ("Receive and verify Cloudinary webhooks") and when ("Use when setting up a Cloudinary notification receiver, verifying..., debugging..., or handling notification_type events") with four concrete trigger phrases, exactly matching the anchor-5 pattern.

5 / 5

Trigger Term Quality

Comprehensive natural-term coverage with synonyms: "webhooks (notifications)", "x-cld-signature", "x-cld-timestamp", "cloudinary SDK", "signature verification failures", and concrete event names users would mention when asking about these events.

5 / 5

Distinctiveness Conflict Risk

Pinned to the Cloudinary niche via provider-specific headers and event names, making it clearly distinguishable even from sibling webhook skills (stripe, shopify) in the same family; minimal conflict risk.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.