CtrlK
BlogDocsLog inGet started
Tessl Logo

stripe-webhooks

Receive and verify Stripe webhooks. Use when setting up Stripe webhook handlers, debugging signature verification, or handling payment events like payment_intent.succeeded, customer.subscription.created, or invoice.paid.

64

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body nails the core: concise, executable verification code for both Node and Python with the raw-body gotcha and error semantics called out, plus real reference files for depth. It is dragged down by padding — a redundant event-types table, attribution boilerplate, and long lists of external sibling-skill links — and by deferring handler examples to paths that are absent from the bundle.

Suggestions

Trim the Common Event Types table (or move it to references/overview.md) — Claude already knows standard Stripe event names, and the section already links the official event reference.

Remove or collapse the Attribution boilerplate, the Recommended webhook-handler-patterns promo, and the 11-entry Related Skills list into a short 2-3 line footer to cut non-instructional tokens.

Fix or inline the examples/express|nextjs|fastapi links — they point to paths not present in the bundle, so the promised complete handler wiring is unreachable; consider a minimal inline Express or FastAPI route example instead.

DimensionReasoningScore

Conciseness

The core Verification section is lean and high-value (raw-body requirement, error semantics), but roughly a third of the body does not earn its tokens: the Common Event Types table restates Stripe knowledge Claude already has, and the Attribution, Recommended, and 11-entry Related Skills sections are promotional padding.

3 / 5

Actionability

The Node and Python verification snippets are executable and copy-paste ready, with concrete env vars and a runnable tunnel command; the gap is that full handler wiring is deferred to examples/express|nextjs|fastapi links that do not exist in this bundle.

4 / 5

Workflow Clarity

The critical step (verify via the SDK helper with the raw body) is unambiguous and includes explicit failure feedback ("Throws/Raises SignatureVerificationError on tampering or stale timestamp"), and supporting steps (env vars, dashboard setup, tunnel, event handling) are all present — but as sections rather than an explicitly ordered sequence with a validate-fix-retry loop.

4 / 5

Progressive Disclosure

SKILL.md is a true overview with three real, one-level-deep, clearly labeled reference files (overview.md, setup.md, verification.md) matching the actual bundle; deductions for the examples/* links that are broken in this bundle and the heavy cross-skill external link sections.

4 / 5

Total

15

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person, concise, explicit "what" plus a concrete "Use when" clause with real Stripe event names as triggers. The only weaknesses are slightly narrow capability coverage and a few missing natural trigger variations.

DimensionReasoningScore

Specificity

"Receive and verify Stripe webhooks" names concrete core actions, and the trigger clause adds "setting up Stripe webhook handlers, debugging signature verification, or handling payment events" with specific event names — several specific actions with only minor capability gaps (e.g., endpoint configuration or local testing not named as capabilities).

4 / 5

Completeness

It explicitly answers both "what" ("Receive and verify Stripe webhooks") and "when" ("Use when setting up Stripe webhook handlers, debugging signature verification, or handling payment events...") with concrete trigger phrases, matching the top anchor's example structure.

5 / 5

Trigger Term Quality

Natural terms users would actually say — "stripe webhooks", "webhook handlers", "signature verification", and exact event names like payment_intent.succeeded — are present, but a few common variations ("webhook endpoint", "test webhooks locally", "Stripe CLI") are missing.

4 / 5

Distinctiveness Conflict Risk

"Stripe" is pinned in every phrase, giving a clear niche with distinct triggers and minimal conflict risk even against closely related sibling skills like shopify-webhooks or chargebee-webhooks.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 3 missing

Warning

Total

15

/

16

Passed

Repository
hookdeck/webhook-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.