CtrlK
BlogDocsLog inGet started
Tessl Logo

sendgrid-webhooks

Receive and verify SendGrid webhooks. Use when setting up SendGrid webhook handlers, debugging signature verification, or handling email delivery events.

68

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong, execution-focused skill body with genuinely copy-paste-ready verification code in two flavors and well-organized references. Its main issues are a dangling reference to a nonexistent examples/ directory, a slightly redundant second Express handler, and the absence of an explicit end-to-end workflow or signature-failure recovery guidance.

Suggestions

Fix the progressive disclosure gap: either add the referenced examples/ directory (Express, Next.js, FastAPI implementations) or remove the 'examples/' entry from the Resources section, since it currently points to nothing in the bundle.

Tighten conciseness by collapsing the two Express route handlers into one shared example and dropping the ECDSA acronym expansion, leaving just 'SendGrid signs webhooks with ECDSA; verify with the public key.'

Add a short numbered workflow (get verification key in dashboard → set env var → implement handler with raw body → test via hookdeck-cli) with a pointer to references/verification.md for signature-failure debugging to lift workflow clarity.

DimensionReasoningScore

Conciseness

The body is efficient overall — a dense event-type table, no basic-concept padding, and code that earns its tokens. Minor trimmable content keeps it out of the lean-every-token anchor: the ECDSA acronym expansion ('Elliptic Curve Digital Signature Algorithm') explains something Claude already knows, and the SDK section repeats a full Express route handler that differs from the manual example by only a few lines.

4 / 5

Actionability

Both code paths are complete and executable: a manual crypto verifier with PEM-wrapping logic, an SDK variant, the exact signature header names, the raw-body middleware requirement, an env var with a sample value, and a runnable CLI command for local testing ('npx hookdeck-cli listen 3000 sendgrid'). This is copy-paste-ready and covers the common cases (manual vs. SDK), matching the fully-executable anchor.

5 / 5

Workflow Clarity

The handler code embeds explicit validation checkpoints — missing-header check returns 400, invalid signature returns 400 — giving a clear sequence with most checkpoints present. It is not a 5 because there is no numbered end-to-end workflow (configure key in dashboard → implement handler → verify → test locally) and no error-recovery guidance (e.g., what to check when verification fails), which is delegated to references/verification.md.

4 / 5

Progressive Disclosure

The three real bundle files (references/overview.md, setup.md, verification.md) are one level deep and clearly signaled with one-line descriptions of what each contains, matching the good-structure anchor. The gap preventing a 5: the Resources section links 'examples/ - Complete implementations for Express, Next.js, and FastAPI' but no examples/ directory exists in the bundle — a dangling reference that breaks navigation.

4 / 5

Total

17

/

20

Passed

Description

82%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A concise, well-structured description with an explicit trigger clause and strong niche focus. Its main weakness is limited action breadth in the 'what' statement — 'Receive and verify' covers only two actions, leaving the full capability surface (event processing, key setup) to be inferred from the trigger list.

Suggestions

Expand the 'what' clause with one or two more concrete actions (e.g., 'process delivery and engagement events, configure verification keys') to lift specificity from anchor 3 to 4.

Add a natural synonym or file-extension-adjacent trigger term such as 'Twilio Email Event Webhook' or 'inbound email events' to broaden trigger coverage toward the anchor-5 level.

DimensionReasoningScore

Specificity

The description names the domain ('SendGrid webhooks') and exactly two concrete actions ('Receive and verify'), which matches the anchor for 1-2 concrete actions without comprehensive coverage. It does not list several specific actions such as event processing, key configuration, or engagement analytics, so it is not a 4.

3 / 5

Completeness

It clearly answers 'what' ('Receive and verify SendGrid webhooks') and 'when' with an explicit 'Use when' clause listing three concrete trigger scenarios (setting up handlers, debugging signature verification, handling delivery events). This matches the anchor that explicitly answers both what and when with concrete trigger phrases.

5 / 5

Trigger Term Quality

Natural user phrases like 'SendGrid webhook handlers', 'debugging signature verification', and 'email delivery events' give good keyword coverage. Common variations and synonyms such as 'event webhooks', 'Twilio Email Event Webhook', or 'ECDSA verification' are missing, so it falls short of the comprehensive-synonyms anchor at 5.

4 / 5

Distinctiveness Conflict Risk

It occupies a clear niche (SendGrid-specific webhooks) with every trigger phrase provider-qualified, so risk of firing for a competing email-webhook skill (Mailgun, Postmark, SES) is minimal. All triggers are anchored to 'SendGrid', distinguishing it from generic webhook skills.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 1 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.