webhook-security
Implements security best practices for receiving third-party webhooks to prevent spoofing and duplicate processing.
Install
mkdir -p .claude/skills/webhook-security && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/4905" && unzip -o skill.zip -d .claude/skills/webhook-security && rm skill.zipInstalls to .claude/skills/webhook-security
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Implement secure webhook handling with signature verification, replay protection, and idempotency. Use when receiving webhooks from third-party services like Stripe, GitHub, Twilio, or building your own webhook system.Key capabilities
- →Verify HMAC-SHA256 signatures
- →Validate request timestamps
- →Implement idempotency checks
- →Prevent replay attacks
- →Perform constant-time comparisons
How it works
It implements a multi-layer security pipeline including signature verification, timestamp validation, and idempotency checks to ensure secure webhook processing.
Inputs & outputs
When to use webhook-security
- →Verifying Stripe webhook signatures
- →Implementing idempotency keys
- →Adding replay protection to API listeners
- →Validating incoming request security
About webhook-security
Provides mechanisms to verify webhook signatures and ensure message integrity. It helps developers implement idempotency and protection against replay attacks when consuming external APIs.
Implement secure webhook handling with signature verification, replay protection, and idempotency. Use when receiving webhooks from third-party services like Stripe, GitHub, Twilio, or building your own webhook system.
When not to use it
- →Parsing JSON before verification
- →Exposing secrets in logs
Prerequisites
Limitations
- →Requires raw body access
- →Strict 5-minute timestamp tolerance
How it compares
It enforces a defense-in-depth approach, specifically preventing common vulnerabilities like timing attacks and replay attacks.
Compared to similar skills
webhook-security side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| webhook-security (this skill) | 1 | 7mo | Caution | Advanced |
| api-security-best-practices | 15 | 8mo | Review | Intermediate |
| api-security-hardening | 0 | 7mo | Review | Intermediate |
| file-uploads | 4 | 8mo | No flags | Advanced |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by dadbodgeoff
View all by dadbodgeoff →You might also like
api-security-best-practices
davila7
Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities
api-security-hardening
aj-geddes
>
file-uploads
davila7
Expert at handling file uploads and cloud storage. Covers S3, Cloudflare R2, presigned URLs, multipart uploads, and image optimization. Knows how to handle large files without blocking. Use when: file upload, S3, R2, presigned URL, multipart.
graphql
davila7
GraphQL gives clients exactly the data they need - no more, no less. One endpoint, typed schema, introspection. But the flexibility that makes it powerful also makes it dangerous. Without proper controls, clients can craft queries that bring down your server. This skill covers schema design, resolvers, DataLoader for N+1 prevention, federation for microservices, and client integration with Apollo/urql. Key insight: GraphQL is a contract. The schema is the API documentation. Design it carefully.
solana-dev
mashharuki
Use when user asks to "build a Solana dapp", "write an Anchor program", "create a token", "debug Solana errors", "set up wallet connection", "test my Solana program", "deploy to devnet", or "explain Solana concepts" (rent, accounts, PDAs, CPIs, etc.). End-to-end Solana development playbook covering
solana-dev
solanabr
Unified skill hub for Solana development. Routes to external submodule skills (solana-foundation, sendai, solana-game, trailofbits, cloudflare, qedgen, colosseum) and local skills. Progressive disclosure — read only what you need.