CtrlK
BlogDocsLog inGet started
Tessl Logo

openai-webhooks

Receive and verify OpenAI webhooks. Use when setting up OpenAI webhook handlers for fine-tuning jobs, batch completions, or async events like fine_tuning.job.completed, batch.completed, or realtime.call.incoming.

67

Quality

84%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Highly actionable content with exemplary, security-correct code and a clean reference structure. The main deductions are token padding from cross-promotional link sections and a duplicated second-language implementation, plus example-directory links that dangle in this bundle.

Suggestions

Trim the 'Related Skills' catalog and 'Recommended: webhook-handler-patterns' sections to 1–2 most-relevant links (or move them to a references file) to cut non-task tokens.

Move one of the two full handler implementations (Express or FastAPI) into the examples/ directory and keep only a pointer in SKILL.md, or actually include the example files so the existing links resolve.

Add a brief recovery note after signature verification (e.g., how to respond to malformed payloads and whether to log-and-acknowledge or reject) to close the workflow validation gaps.

DimensionReasoningScore

Conciseness

The code and tables are dense with value, but there is noticeable padding: a full duplicate handler implementation (Express and FastAPI), an 11-link "Related Skills" catalog, a "Recommended" section with four more outbound GitHub links, and an attribution block — none of which help complete the task. Fits 'mostly efficient but could be tightened'; not 4 because the promotional/navigation sections and duplicated implementation are more than minor trims.

3 / 5

Actionability

Fully executable, copy-paste-ready handlers in two languages with real signature verification (replay window, whsec_ decoding, timing-safe compare), the critical express.raw() detail, an event-type dispatch table, env vars, and a local-tunnel command. Covers the common cases completely.

5 / 5

Workflow Clarity

The sequence verify → parse → handle is explicit and commented in the code, with the raw-body prerequisite flagged ("CRITICAL: Use express.raw()..."). Not 5 because there are no explicit recovery checkpoints (e.g., JSON.parse failures are unhandled, no guidance on retrying or logging rejected signatures), but the core order and validation are clear.

4 / 5

Progressive Disclosure

Good structure: an overview body with well-labeled one-level-deep references (references/overview.md, setup.md, verification.md — all present as real files with substantive content). Not 5 because the body links to examples/express/, examples/nextjs/, and examples/fastapi/ which do not exist in the bundle, and two complete handler implementations are inlined that could partly live in those example files.

4 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong third-person description that pairs a concise what with an explicit 'Use when' clause naming concrete trigger events. Only minor gaps: a few natural keyword variants are absent and one listed event name ("fine_tuning.job.completed") does not match the actual event naming used in the body.

DimensionReasoningScore

Specificity

Concrete actions are named — "Receive and verify OpenAI webhooks", "setting up OpenAI webhook handlers" — plus specific event types (fine_tuning, batch, realtime). Not a 5 because only two verbs cover the capability space and the enumerated events partially repeat the domains already named; not a 3 because it goes well beyond naming the domain with specific operations and event names.

4 / 5

Completeness

Explicitly answers what ("Receive and verify OpenAI webhooks") and when ("Use when setting up OpenAI webhook handlers for fine-tuning jobs, batch completions, or async events like...") with concrete trigger event names. Matches the anchor-5 pattern of what + when with concrete trigger phrases; a 4 would require the 'when' to be less explicit than it is here.

5 / 5

Trigger Term Quality

Natural terms users would say are present: "OpenAI webhooks", "fine-tuning jobs", "batch completions", "realtime.call.incoming", plus literal event names. Not a 5 because common phrasings like "webhook signature verification failure" or "webhook endpoint/handler" as plain keywords are missing; well above 3 given both domain phrases and exact event identifiers appear.

4 / 5

Distinctiveness Conflict Risk

"OpenAI webhooks" is a clear, provider-specific niche with distinct triggers (OpenAI event names), distinguishable from sibling webhook skills (Stripe, Shopify, etc.). Minimal conflict risk; matches the clear-niche anchor.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.