CtrlK
BlogDocsLog inGet started
Tessl Logo

shopify-webhooks

Receive and verify Shopify webhooks. Use when setting up Shopify webhook handlers, debugging signature verification, or handling store events like orders/create, products/update, or customers/create.

67

Quality

84%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The core content is excellent — executable verification code in two languages, a useful topic table, and a clean split into real reference files. Weaknesses are tail-section padding (attribution, cross-skill promotion, related-skills lists), a time-sensitive API note outside a deprecated section, and delegation to example directories missing from the bundle.

Suggestions

Trim the "Attribution", "Recommended: webhook-handler-patterns", and "Related Skills" sections (or collapse them into 2-3 lines) — they contribute ~25 lines of non-instructional tokens to every skill load.

Remove or relocate the time-sensitive REST-vs-GraphQL note ("apps created after April 1, 2025...") into a clearly labeled deprecated/notes section so it does not go stale in the main flow.

Either include the examples/express, examples/nextjs, and examples/fastapi directories in the bundle or replace those links with an inline minimal handler-wiring snippet, so delegated content actually resolves.

DimensionReasoningScore

Conciseness

The instructional core (verification code for Node and Python, topic table, env var, tunnel command) is lean, but the tail pads tokens with an "Attribution" section, a promotional "Recommended: webhook-handler-patterns" section with four GitHub links, ten "Related Skills" links, and a time-sensitive REST-vs-GraphQL date note that is not placed in a deprecated section. This matches anchor 3 (mostly efficient but could be tightened); the padding is confined to non-instructional sections rather than pervasive, so it is not a 2.

3 / 5

Actionability

Both the Node and Python verify functions are complete and copy-paste executable (including timing-safe comparison and missing-header guards), and "npx hookdeck-cli listen 3000 shopify --path /webhooks/shopify" and SHOPIFY_API_SECRET are concrete, covering the common verification and local-testing cases. This fits anchor 5.

5 / 5

Workflow Clarity

The core verification action is unambiguous — pass the raw body, decode base64, compare timing-safe, respond 200 within 5 seconds — but the fuller handler workflow (route wiring, event dispatch, tests) is only delegated to examples/ directories that are not present in the bundle, with no inline sequence or checkpoints. It sits between anchor 4 (clear sequence, minor gaps) and anchor 5 (unambiguous single action), and the missing inline steps for the promised handler setup keep it at 4.

4 / 5

Progressive Disclosure

Good structure: overview content inline, details split into real one-level-deep references (overview.md, setup.md, verification.md) that are clearly labeled in a "Reference Materials" section with no nesting. It falls short of anchor 5 because the body links to examples/express/, examples/nextjs/, and examples/fastapi/ directories that do not exist in the bundle, and the "Recommended" section points only to GitHub-hosted files of another skill.

4 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete capabilities, explicit "Use when" triggers with named Shopify topics, and a clearly distinct niche. Only minor keyword variants are missing from an otherwise excellent trigger surface.

DimensionReasoningScore

Specificity

"Receive and verify Shopify webhooks" plus "setting up Shopify webhook handlers, debugging signature verification, or handling store events like orders/create" lists several concrete actions with named topics. It falls short of anchor 5 only because coverage has minor gaps (e.g., no mention of payload handling or local-development tunneling).

4 / 5

Completeness

It explicitly answers both what ("Receive and verify Shopify webhooks") and when ("Use when setting up Shopify webhook handlers, debugging signature verification, or handling store events like...") with concrete trigger phrases, matching the anchor-5 example pattern.

5 / 5

Trigger Term Quality

Natural trigger phrases like "Shopify webhooks", "webhook handlers", "signature verification", "orders/create", "products/update", and "customers/create" give good keyword coverage. A few natural variants users might say (e.g., "webhook endpoint", "webhook payload", "HMAC") are missing, so it fits anchor 4 rather than 5.

4 / 5

Distinctiveness Conflict Risk

"Shopify" plus "webhooks" carves out a clear niche with distinct triggers (Shopify-specific topics and headers), making confusion with sibling skills (stripe-webhooks, github-webhooks) unlikely.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.