CtrlK
BlogDocsLog inGet started
Tessl Logo

deepgram-webhooks

Receive and verify Deepgram webhooks (callbacks). Use when setting up Deepgram webhook handlers, processing transcription callbacks, or handling asynchronous transcription results.

68

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Strong, execution-focused content: complete code, concrete auth logic, and accurate operational constraints with well-organized references. The two real flaws are a dangling reference to a nonexistent examples/ directory and some repetition of the dg-token caveat across sections.

Suggestions

Fix or remove the dangling reference to examples/ in the Resources section — that directory is not present in the bundle, so the link promises Express, Next.js, and FastAPI implementations that do not exist.

State the dg-token caveat ("not guaranteed on every callback request, check only when present") once — e.g., in Authentication Methods — and drop the repeats in the handler comment and the No Signature Verification section to tighten conciseness.

Add a short end-to-end verification step (start the local tunnel, send the curl request, confirm the handler logs the request_id) to close the workflow with an explicit test checkpoint.

DimensionReasoningScore

Conciseness

The body is lean and assumes competence (e.g., uses timingSafeEqual without explaining timing attacks), but the dg-token caveat is repeated three times — handler comment, Authentication Methods, and No Signature Verification — which is trimmable redundancy; there is no explanatory padding that would warrant a 3.

4 / 5

Actionability

Fully executable guidance throughout: a complete Express handler with timing-safe Basic Auth checks, a copy-paste curl request with callback URL, an environment variable block, and a working local-tunnel command. Common cases are covered end-to-end.

5 / 5

Workflow Clarity

The sequence (implement handler with auth checks → make request with callback → parse payload → test locally) is coherent with explicit checkpoints (401/403 on auth failure, returning 200 to prevent retries, allowed ports). It lacks an explicit end-to-end test/verify feedback loop, keeping it below the top anchor.

4 / 5

Progressive Disclosure

The body is a clean overview with well-signaled, one-level-deep references that all exist (overview.md, setup.md, verification.md). However, the Resources section links examples/ ("Complete implementations for Express, Next.js, and FastAPI") which is absent from the bundle — a dangling reference that keeps it below the top anchor.

4 / 5

Total

17

/

20

Passed

Description

82%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A well-formed description with an explicit 'Use when' trigger clause, third-person voice, and a clearly bounded Deepgram-specific niche. The only weakness is that the capability statement covers just two actions, making it less comprehensive than the trigger coverage suggests.

DimensionReasoningScore

Specificity

The description names the domain plus exactly two concrete actions ("Receive and verify Deepgram webhooks (callbacks)"), matching the 1-2-actions anchor rather than the several-actions level; capabilities like setup, retry handling, or local testing are not named in the what-clause.

3 / 5

Completeness

It clearly answers what ("Receive and verify Deepgram webhooks (callbacks)") and when ("Use when setting up Deepgram webhook handlers, processing transcription callbacks, or handling asynchronous transcription results") with concrete trigger phrases, matching the top anchor.

5 / 5

Trigger Term Quality

Natural phrases users would say are present ("webhook handlers", "transcription callbacks", "asynchronous transcription results"), but common variations like "callback URL" or "speech-to-text results" are missing, so it sits between good and comprehensive coverage.

4 / 5

Distinctiveness Conflict Risk

The provider name "Deepgram" is embedded in both the what and every trigger phrase, giving a clear niche with minimal overlap risk even against sibling webhook skills (stripe-webhooks, shopify-webhooks, github-webhooks).

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 1 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.