AgentStack
SKILL verified MIT Self-run

Webhook Subscriptions

skill-martin-hausleitner-martins-awesome-skills-webhook-subscriptions · by Martin-Hausleitner

Use when external services should trigger agent runs through webhook events

No reviews yet
0 installs
12 views
0.0% view→install

Install

$ agentstack add skill-martin-hausleitner-martins-awesome-skills-webhook-subscriptions

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Webhook Subscriptions? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Webhook Subscriptions

Overview

Webhook-triggered agents are powerful because they turn external events into work. Treat every webhook as an untrusted public input unless proven otherwise.

Setup Pattern

  1. Confirm the gateway or webhook receiver is available.
  2. Generate a strong per-subscription secret outside the repo.
  3. Subscribe to the smallest event set that solves the task.
  4. Test with a synthetic payload.
  5. Log only event metadata, not secret headers or private payload fields.

Example Shape

hermes webhook subscribe repo-issues \
  --events "issues" \
  --prompt "Triage this issue event and propose next steps." \
  --skills "github-issues,github-code-review"

Verification

hermes webhook list
hermes webhook test repo-issues --payload '{"action":"opened"}'

Safety

  • Require HMAC validation or an equivalent signature check.
  • Keep webhook secrets in environment variables or a private config file.
  • Do not commit event payloads from production systems.
  • Prefer dry-run delivery until the prompt is proven safe.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.