CtrlK
BlogDocsLog inGet started
Tessl Logo

cloudsignal-webhooks

Receive and verify CloudSignal webhooks from Cloudprinter.com. Use when setting up a CloudSignal Webhooks v2.0 receiver, authenticating deliveries by the plaintext `apikey` field in the JSON body (there is NO HMAC signature header), or handling print order/item status signals like CloudprinterOrderValidated, ItemProduced, ItemShipped, ItemError, and ItemCanceled.

67

Quality

84%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, dense overview with executable verification code, precise retry/ack semantics, and a complete signal-type table, backed by real one-level-deep reference files. The main defects are the missing examples/ directories referenced in the body, the handler sequence being delegated to an external skill, and small amounts of promotional boilerplate.

Suggestions

Bundle the examples/express/, examples/nextjs/, and examples/fastapi/ directories referenced in the body, or remove/redirect those links — 'For complete handlers with tests' currently points nowhere in this skill.

Inline a minimal complete handler sequence (authenticate via body.apikey → parse → respond 200 → process idempotently) instead of delegating the ordering entirely to the external webhook-handler-patterns skill.

Trim the Attribution section and the seven-item Related Skills list to reduce token overhead that adds little decision-relevant guidance.

DimensionReasoningScore

Conciseness

The body is lean and code-forward, assumes Claude's competence, and includes genuinely non-obvious gotchas (no HMAC, SDK is standalone-only). Minor trims are possible — the Attribution boilerplate and the 7-link promotional Related Skills list — so it matches anchor 4 rather than 5.

4 / 5

Actionability

Executable, copy-paste-ready timing-safe verification code, a concrete env var, a runnable hookdeck CLI command, exact ack/retry semantics (200/204, 401, 100 attempts/7 days), and a complete signal-type table. Not 5: 'For complete handlers with tests, see examples/express/...' points to directories absent from the bundle, and no full route handler is inlined.

4 / 5

Workflow Clarity

The verify → acknowledge → handle flow is unambiguous with error semantics documented (return 401 on bad key; non-200 triggers retries), but the full handler sequence and idempotency ordering ('Authenticate first, parse second, handle idempotently third') is delegated to an external skill rather than stated inline. Clear sequence with minor validation gaps matches anchor 4.

4 / 5

Progressive Disclosure

Good structure: an overview body with a well-signaled Reference Materials section pointing to three real, one-level-deep reference files (overview.md, setup.md, verification.md) that each exist in the bundle. Minor organization gap: the examples/express/, examples/nextjs/, and examples/fastapi/ links are broken in the bundle, so it falls short of anchor 5's 'easy navigation'.

4 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete actions, an explicit 'Use when' clause with three trigger scenarios, provider-specific terms, and effective disambiguation from both sibling webhook skills and the similarly-named cloudsignal.io platform. Only minor gaps in capability coverage and a few missing synonyms keep it from perfect scores.

DimensionReasoningScore

Specificity

Concrete actions are named — 'Receive and verify CloudSignal webhooks', 'authenticating deliveries by the plaintext `apikey` field in the JSON body' — and specific signal names are listed. Falls just short of anchor 5 because coverage omits peripheral actions like endpoint registration and retry handling.

4 / 5

Completeness

Explicitly answers both: what ('Receive and verify CloudSignal webhooks from Cloudprinter.com') and when ('Use when setting up a CloudSignal Webhooks v2.0 receiver, authenticating deliveries..., or handling print order/item status signals...'). Matches the anchor-5 example structure; the 'when' clause is explicit with concrete triggers, so not 4.

5 / 5

Trigger Term Quality

Good natural keywords: 'CloudSignal webhooks', 'Cloudprinter.com', 'apikey', 'HMAC', and event names users would actually type (ItemShipped, ItemError). A few natural variations are missing (e.g., 'print order status', 'webhook signature'), so it matches anchor 4 rather than 5.

4 / 5

Distinctiveness Conflict Risk

Names a clear niche — Cloudprinter.com's CloudSignal Webhooks v2.0 — with the auth scheme and signal names making confusion with sibling webhook skills (Stripe, Shopify, etc.) or the unrelated cloudsignal.io platform unlikely. Minimal conflict risk.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.