CtrlK
BlogDocsLog inGet started
Tessl Logo

github-webhooks

Receive and verify GitHub webhooks. Use when setting up GitHub webhook handlers, debugging signature verification, or handling repository events like push, pull_request, issues, or release.

63

Quality

79%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/github-webhooks/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

68%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong, lean reference-style skill whose core is genuinely excellent: executable, correct signature-verification code and immediately usable commands. It loses points on the periphery — promotional cross-links and attribution padding, no explicit handler sequence, and dead examples/ paths relative to the actual bundle.

Suggestions

Add a short numbered handler workflow in the body (receive raw body → verify signature → parse event by X-GitHub-Event → dispatch to handler → respond 200) so the sequence and the verify-first checkpoint are explicit rather than deferred to the examples.

Fix or remove the examples/express/, examples/nextjs/, and examples/fastapi/ links — these paths do not exist in the bundle, so either ship the files, point to the GitHub repo URLs, or drop the pointer to the three reference files.

Trim the 11-item Related Skills list and the Attribution block (or move them to a single reference file) — they consume context without changing what Claude does for this task.

DimensionReasoningScore

Conciseness

The verification core, tables, and commands are lean, but there is real padding: an 11-item "Related Skills" cross-promotion list, a "Recommended" section that repeats one of those skills, and an "Attribution" block — none of which help Claude execute the task. This is 'mostly efficient but includes some unnecessary content' rather than merely minor trimmable instances.

3 / 5

Actionability

Two complete, copy-paste-ready verification functions (Node and Python) with correct raw-body, sha256, and timing-safe handling, plus a runnable tunnel command (`npx hookdeck-cli listen 3000 github --path /webhooks/github`) and a concrete env var. The common cases are covered by executable code.

5 / 5

Workflow Clarity

The body is organized topically (verification, events, headers, env, dev) rather than as a sequenced handler workflow; the receive → verify → parse → dispatch order is only implied and deferred to the examples/ directories, with no explicit checkpoints in this file. That matches 'sequence present but implicit; checkpoints missing'.

3 / 5

Progressive Disclosure

The three references/*.md links are real, one-level-deep, and clearly signaled with short descriptions — good overview structure. However, the 'examples/express/', 'examples/nextjs/', and 'examples/fastapi/' links point to paths that do not exist in the bundle, breaking navigation for the promised complete handlers, which is more than a purely minor gap.

4 / 5

Total

15

/

20

Passed

Description

82%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A well-crafted description in the style of the reference good examples: concise, third-person, with an explicit 'Use when' clause covering setup, debugging, and event-handling triggers. Its only weakness is a thin 'what' — just two capabilities (receive, verify) — which limits specificity rather than completeness.

DimensionReasoningScore

Specificity

The description names the domain and exactly two concrete actions — "Receive and verify GitHub webhooks" — matching the '1-2 concrete actions, but not comprehensive' anchor; the remaining detail is trigger context rather than additional capabilities, so it does not reach the 'several specific actions' level.

3 / 5

Completeness

It explicitly answers both questions: what ("Receive and verify GitHub webhooks") and when ("Use when setting up GitHub webhook handlers, debugging signature verification, or handling repository events like push, pull_request, issues, or release") with concrete trigger phrases, mirroring the top anchor's structure.

5 / 5

Trigger Term Quality

Strong natural phrases users would actually say: "setting up GitHub webhook handlers", "debugging signature verification", and event names "push, pull_request, issues, or release". A few common companion terms (payload, endpoint, HMAC, callback) are absent, keeping it at 'good coverage; a few natural terms missing' rather than comprehensive.

4 / 5

Distinctiveness Conflict Risk

"GitHub" scopes the niche tightly and the triggers (GitHub webhook handlers, GitHub repository events, signature verification) are distinct from sibling webhook skills (Stripe, Shopify, etc.), giving a clear niche with minimal conflict risk.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.