Webhook subscriptions
Skill Martin-Hausleitner/martins-awesome-skills/skills/devops/webhook-subscriptions
Martin's Awesome Skills: public-safe Hermes and OpenClaw agent skills with Telegram approval workflows
npx -y skills add Martin-Hausleitner/martins-awesome-skills --skill webhook-subscriptionsAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Use when external services should trigger agent runs through webhook events
SKILL.md
1.2 KB, as published. Nobody here has run it
Webhook Subscriptions
Overview
Webhook-triggered agents are powerful because they turn external events into work. Treat every webhook as an untrusted public input unless proven otherwise.
Setup Pattern
- Confirm the gateway or webhook receiver is available.
- Generate a strong per-subscription secret outside the repo.
- Subscribe to the smallest event set that solves the task.
- Test with a synthetic payload.
- Log only event metadata, not secret headers or private payload fields.
Example Shape
hermes webhook subscribe repo-issues \
--events "issues" \
--prompt "Triage this issue event and propose next steps." \
--skills "github-issues,github-code-review"
Verification
hermes webhook list
hermes webhook test repo-issues --payload '{"action":"opened"}'
Safety
- Require HMAC validation or an equivalent signature check.
- Keep webhook secrets in environment variables or a private config file.
- Do not commit event payloads from production systems.
- Prefer dry-run delivery until the prompt is proven safe.