# Webhook Subscriptions

> Use when external services should trigger agent runs through webhook events

- Skill: `martin-hausleitner/webhook-subscriptions` (Agent Skill)
- Install (CLI): `npx skillmds@latest add martin-hausleitner/webhook-subscriptions`
- Raw SKILL.md: https://api.skillmd.com/api/skills/martin-hausleitner/webhook-subscriptions/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: AI & ML
- Author: Martin-Hausleitner (https://skillmd.com/u/martin-hausleitner)
- Updated: 2026-09-22
- Page: https://skillmd.com/skills/martin-hausleitner/webhook-subscriptions

---


# Webhook Subscriptions

## Overview

Webhook-triggered agents are powerful because they turn external events into work. Treat every webhook as an untrusted public input unless proven otherwise.

## Setup Pattern

1. Confirm the gateway or webhook receiver is available.
2. Generate a strong per-subscription secret outside the repo.
3. Subscribe to the smallest event set that solves the task.
4. Test with a synthetic payload.
5. Log only event metadata, not secret headers or private payload fields.

## Example Shape

```bash
hermes webhook subscribe repo-issues \
  --events "issues" \
  --prompt "Triage this issue event and propose next steps." \
  --skills "github-issues,github-code-review"
```

## Verification

```bash
hermes webhook list
hermes webhook test repo-issues --payload '{"action":"opened"}'
```

## Safety

- Require HMAC validation or an equivalent signature check.
- Keep webhook secrets in environment variables or a private config file.
- Do not commit event payloads from production systems.
- Prefer dry-run delivery until the prompt is proven safe.

