CtrlK
BlogDocsLog inGet started
Tessl Logo

webhooks

Add, debug, and manage webhook providers in the joelclaw webhook gateway. Use when: adding a new webhook integration (GitHub, Stripe, Vercel, etc.), debugging webhook signature failures, checking webhook delivery, testing webhook endpoints, registering webhooks with external services, or reviewing webhook provider implementations. Triggers on: 'add a webhook', 'new webhook provider', 'webhook not working', 'webhook signature failed', 'register webhook', 'webhook debug', 'verify webhook', 'add Vercel/GitHub/Stripe webhook', 'webhook 401', 'test webhook endpoint', or any external service webhook integration task.

72

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A strong operational skill body: nearly everything is executable commands, real paths, and environment-specific gotchas rather than generic explanation, and detailed procedure is properly pushed to a single well-organized reference file. Remaining gaps are duplication between the two signature tables, version-sensitive details outside a deprecated section, and validation/feedback loops that live only in the reference.

Suggestions

Merge the "Current Providers" and "Signature Algorithms by Provider" tables (or drop signature/encoding columns from the first) to remove duplicated details and save tokens.

Move the per-service registration walkthroughs (Vercel API curl, GitHub, Todoist, Front) into a references file alongside the provider checklist, keeping only the stable URL and secret-storage convention in the body.

Inline a short fix-and-retry loop in the Debugging section (e.g., after a signature failure, re-test with the manual HMAC command before checking Inngest) so error recovery doesn't depend on opening the reference file.

DimensionReasoningScore

Conciseness

Largely efficient — tables, commands, and repo-specific gotchas with no explanation of concepts Claude already knows — but signature/encoding details are duplicated between the "Current Providers" and "Signature Algorithms" tables, the Vercel URL repeats three times, and the bare version note "agent-secrets v0.5.0+" adds time-sensitive detail outside any deprecated/old-patterns section.

4 / 5

Actionability

Fully executable guidance throughout: a copy-paste-ready openssl+curl HMAC test with real headers, concrete joelclaw CLI commands ("joelclaw logs worker --follow --grep webhook", "joelclaw inngest restart-worker --register"), a complete Vercel API registration payload, and exact file paths in the Key Files table.

5 / 5

Workflow Clarity

The 8-step add-provider sequence is clearly numbered with an explicit final validation step ("8. Verify E2E with curl + real webhook") and a migration checkpoint ("do not declare a provider migrated until a real signed delivery succeeds"), but intermediate checkpoints and error-recovery feedback loops are deferred to the reference file rather than present in the body.

4 / 5

Progressive Disclosure

The body works as an overview with one clearly signaled, one-level-deep reference ("See [references/new-provider-checklist.md]... for the full 8-step checklist") that exists and is not nested, but the full signature-algorithm table and per-service registration guides could arguably live in separate references, and the assets/ files are never referenced from the body.

4 / 5

Total

17

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An exemplary description: concrete actions, an explicit Use-when clause, and an extensive natural trigger list in third-person imperative voice. The only weakness is that several trigger phrases are generic webhook terms whose disambiguation rests entirely on the joelclaw qualifier.

DimensionReasoningScore

Specificity

"Add, debug, and manage webhook providers" plus enumerated actions ("debugging webhook signature failures, checking webhook delivery, testing webhook endpoints, registering webhooks with external services, or reviewing webhook provider implementations") gives multiple concrete actions with comprehensive coverage of the domain.

5 / 5

Completeness

Explicitly answers "what" ("Add, debug, and manage webhook providers in the joelclaw webhook gateway") and "when" via both a "Use when:" clause and a "Triggers on:" list with concrete trigger phrases, matching the anchor-5 example pattern.

5 / 5

Trigger Term Quality

The trigger list is comprehensive and natural: "'add a webhook'", "'webhook not working'", "'webhook signature failed'", "'webhook 401'", "'add Vercel/GitHub/Stripe webhook'" — covering synonyms, provider names, and colloquial phrasings users would actually say.

5 / 5

Distinctiveness Conflict Risk

The "joelclaw webhook gateway" qualifier and named providers create a clear niche, but many trigger phrases ("'register webhook'", "'verify webhook'", "'test webhook endpoint'") are generic webhook vocabulary that any closely related webhook/integration skill would also claim — minor overlap risk.

4 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
joelhooks/joelclaw
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.