Webhook subscriptions
Skill Martin-Hausleitner/martins-awesome-skills/skills/devops/webhook-subscriptions
Use when external services should trigger agent runs through webhook eventsFrom its SKILL.md
npx -y skills add Martin-Hausleitner/martins-awesome-skills --skill webhook-subscriptionsAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- 3 stars3 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
- runs commandsInstructs the agent to run 3 commands, including `hermes webhook subscribe repo-issues --events "issues" --prompt "Triage this issue event and propose next steps." --skills "github-issues,github-code-review"` and 2 more.
SKILL.md
1.2 KB, 229 tokens by cl100k_base, as published. Nobody here has run it
Webhook Subscriptions
Overview
Webhook-triggered agents are powerful because they turn external events into work. Treat every webhook as an untrusted public input unless proven otherwise.
Setup Pattern
- Confirm the gateway or webhook receiver is available.
- Generate a strong per-subscription secret outside the repo.
- Subscribe to the smallest event set that solves the task.
- Test with a synthetic payload.
- Log only event metadata, not secret headers or private payload fields.
Example Shape
hermes webhook subscribe repo-issues \
--events "issues" \
--prompt "Triage this issue event and propose next steps." \
--skills "github-issues,github-code-review"
Verification
hermes webhook list
hermes webhook test repo-issues --payload '{"action":"opened"}'
Safety
- Require HMAC validation or an equivalent signature check.
- Keep webhook secrets in environment variables or a private config file.
- Do not commit event payloads from production systems.
- Prefer dry-run delivery until the prompt is proven safe.
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.