CtrlK
BlogDocsLog inGet started
Tessl Logo

paddle-webhooks

Receive and verify Paddle webhooks. Use when setting up Paddle webhook handlers, debugging signature verification, or handling subscription events like subscription.created, subscription.canceled, or transaction.completed.

67

Quality

84%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Medium

Suggest reviewing before use

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable overview whose core verification code is exemplary, with genuine one-level-deep reference files. Weaker points are token waste from the duplicated event table and the Related Skills section, and the absence of an explicit end-to-end handler workflow with a validation checkpoint.

Suggestions

Replace the inline 10-row event table with a 3-4 row sample and a pointer to references/overview.md for the full list, removing the duplication.

Add a short numbered handler workflow (create destination → wire route → verify signature → send a test notification → confirm verification passes and return 200) so the sequence and validation checkpoint are explicit.

Trim the 'Related Skills' list to the few most relevant (e.g., webhook-handler-patterns, stripe-webhooks) and drop the attribution boilerplate to save tokens.

DimensionReasoningScore

Conciseness

The verification section is lean and assumes competence (no explanation of what webhooks or HMAC are), but the 10-row event table is duplicated from references/overview.md and the 10-link 'Related Skills' list plus 'Attribution' section add tokens that don't serve the task. Between 3 ('could be tightened') and 4 ('minor over-explanation'), leaning slightly below the midpoint due to the duplicated table and promotional lists.

3.5 / 5

Actionability

The Node and Python verification functions are complete and copy-paste ready (header parsing, multiple h1= during rotation, timing-safe comparison), the SDK's unmarshal call is named, the env var shows its real format, and the tunnel command is directly executable — matching the 'fully executable, covers common cases' anchor.

5 / 5

Workflow Clarity

Verify-first ordering is established ('Pass the raw body — don't JSON.parse first'; unmarshal verifies and parses in one call) and the Local Development tunnel gives a test path, but the handler sequence (setup destination → wire route → verify → test event → confirm 200) is never laid out and no explicit validation checkpoint exists, e.g. 'send a test notification and confirm verification passes'. Between 3 (checkpoints implicit) and 4 (most checkpoints present).

3.5 / 5

Progressive Disclosure

The body is a well-sectioned overview with three real, one-level-deep references (references/overview.md, setup.md, verification.md) each labeled with what they contain. Not 5: the examples/express|nextjs|fastapi links point outside the bundle (they live in the GitHub repo, not in the skill), and the event table belongs in references/overview.md rather than inline.

4 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong third-person description that states concrete capabilities and an explicit 'Use when...' clause with named trigger events. It is clearly distinguishable from sibling provider-webhook skills; only minor synonym coverage (e.g., 'Paddle notifications') is missing.

DimensionReasoningScore

Specificity

"Receive and verify Paddle webhooks" plus "setting up Paddle webhook handlers, debugging signature verification, or handling subscription events" names several concrete actions with specific event identifiers (subscription.created, transaction.completed). Falls short of 5 because coverage has minor gaps (e.g., no mention of event dispatch, local testing, or payload parsing), and clearly exceeds 3's '1-2 concrete actions' bar.

4 / 5

Completeness

Explicitly answers both: what ("Receive and verify Paddle webhooks") and when ("Use when setting up Paddle webhook handlers, debugging signature verification, or handling subscription events like subscription.created...") with concrete trigger phrases — a direct match for the 5 anchor.

5 / 5

Trigger Term Quality

Natural phrases users would say are present: "Paddle webhooks", "webhook handlers", "signature verification", "subscription events", and concrete event names. Not 5 because common synonyms like "Paddle notifications" (Paddle's own term), "billing events", or "webhook secret" phrasing are missing.

4 / 5

Distinctiveness Conflict Risk

"Paddle" is a named payment provider with provider-specific triggers (Paddle webhook handlers, Paddle-Signature verification), giving it a clear niche with minimal overlap risk against sibling skills (stripe-webhooks, shopify-webhooks, etc.).

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.