Rls Patterns
bybren-llc/safe-agentic-workflow
Row Level Security patterns for database operations. An agent skill from bybren-llc/safe-agentic-workflow.
Agent skill
by jeremylongshore in jeremylongshore/tons-of-skills-marketplace
Operate a Podium webhook receiver that survives the delivery-side failures — forged events without signature verification, replay attacks against a stateless handler, duplicate processing from…
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-webhook-reliability -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace podium-webhook-reliability --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/podium-webhook-reliability .claude/skills/podium-webhook-reliability && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "podium-webhook-reliability" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/podium-webhook-reliability into .claude/skills/podium-webhook-reliability/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "podium-webhook-reliability", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/podium-webhook-reliabilityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-webhook-reliability -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace podium-webhook-reliability --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/.curated/podium-webhook-reliability .agents/skills/podium-webhook-reliability && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "podium-webhook-reliability" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/podium-webhook-reliability into .agents/skills/podium-webhook-reliability/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "podium-webhook-reliability", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-webhook-reliability -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace podium-webhook-reliability --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/.curated/podium-webhook-reliability .cursor/skills/podium-webhook-reliability && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "podium-webhook-reliability" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/podium-webhook-reliability into .cursor/skills/podium-webhook-reliability/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "podium-webhook-reliability", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jeremylongshore/tons-of-skills-marketplace.git --path skills/.curated/podium-webhook-reliability--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-webhook-reliability -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace podium-webhook-reliability --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/.curated/podium-webhook-reliability .gemini/skills/podium-webhook-reliability && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "podium-webhook-reliability" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/podium-webhook-reliability into .gemini/skills/podium-webhook-reliability/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "podium-webhook-reliability", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jeremylongshore/tons-of-skills-marketplace podium-webhook-reliabilityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-webhook-reliability -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/.curated/podium-webhook-reliability .github/skills/podium-webhook-reliability && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "podium-webhook-reliability" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/podium-webhook-reliability into .github/skills/podium-webhook-reliability/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "podium-webhook-reliability", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-webhook-reliability -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace podium-webhook-reliability --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/.curated/podium-webhook-reliability .opencode/skills/podium-webhook-reliability && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "podium-webhook-reliability" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/podium-webhook-reliability into .opencode/skills/podium-webhook-reliability/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "podium-webhook-reliability", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
podium-webhook-reliabilityOperate a Podium webhook receiver that survives the delivery-side failures — forged events without signature verification, replay attacks against a stateless handler, duplicate processing from…
Podium Webhook Reliability is an agent skill from jeremylongshore/tons-of-skills-marketplace. Operate a Podium webhook receiver that survives the delivery-side failures — forged events without signature verification, replay attacks against a stateless handler, duplicate processing from Podium's 24h retry policy, lost events with no dead-letter queue, out-of-order batch deliveries, and timing-attack-vulnerable HMAC compares. Use when building a webhook endpoint for call transcripts, webchat events, conversation lifecycle, or review notifications; hardening an existing handler that processes events twice or…
Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including scripts and reference files (for example `ARD.md`, `PRD.md` and `config/settings.yaml`). Compatibility notes: Designed for Claude Code
It sits in Backend & APIs, covering Webhooks. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteEditBash(curl:*)Bash(jq:*)Bash(python3:*)Bash(redis-cli:*)GrepFrom allowed-tools in the SKILL.md frontmatter.
Ships 4 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3uvicornFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.podium.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
PODIUM_WEBHOOK_SECRETSIGNING_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code
From compatibility in the SKILL.md frontmatter.
Podium Webhook Reliability loads about 4k tokens when it runs, and up to ~9.7k if it reads all its reference files. Until then it costs about 198 tokens; SKILL.md has 1,336 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 1,336 words, ~4,002 tokens.
.claude/skills/podium-webhook-reliability/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.Receive Podium webhooks in production without forged events, double-charged AI side-effects, lost notifications, or out-of-order conversation events. This is not an introductory webhook walkthrough — it is the receiver code your integration runs when Podium retries a 5xx response six times over 24 hours, when a leaked secret lets an attacker POST forged events, when a batch delivery arrives with conversation.deleted ahead of conversation.created, and when on-call needs to drain and replay 800 failed events without re-firing the ones that already succeeded.
The six production failures this skill prevents:
SET NX EX 86400 on the event_id is the cheapest fix that exists.conversation.deleted before conversation.created and the system observes a delete on a contact that does not exist. Within a batch, sort by occurred_at before dispatch; across batches, gate causally-dependent handlers on the precondition existing.received_sig == computed_sig with == short-circuits on the first byte mismatch. An attacker measures response latency to recover the signature byte-by-byte over a few thousand probes. Always use hmac.compare_digest, which is constant-time over the longer of the two inputs.fastapi, uvicorn, httpx, and redis (in-memory fallback for dev is provided)podium-auth instance if your handler needs to call back into the Podium API after processingBuild in this order. Each section neutralizes one production failure mode.
Verify the signature against the raw, unparsed request body. Any framework middleware that JSON-decodes-and-re-encodes before signature check will fail because whitespace and key ordering change. Read the body once, verify, then parse:
import hmac, hashlib
from fastapi import FastAPI, Request, HTTPException, Header
app = FastAPI()
SIGNING_SECRET = os.environ["PODIUM_WEBHOOK_SECRET"].encode("utf-8")
@app.post("/webhooks/podium")
async def receive(request: Request, x_podium_signature: str = Header(None)):
raw = await request.body() # bytes — DO NOT decode/re-encode
if not x_podium_signature:
raise HTTPException(401, "missing X-Podium-Signature")
if not verify_signature(raw, x_podium_signature):
raise HTTPException(401, "signature mismatch")
# ... continue with replay/dedup/dispatchdef verify_signature(body: bytes, header_value: str) -> bool:
# Podium signature header format: "t=<unix_ts>,v1=<hex_hmac>"
# Adapt to current spec — verify against the Podium developer docs at integration time.
parts = dict(p.split("=", 1) for p in header_value.split(",") if "=" in p)
ts, sig = parts.get("t"), parts.get("v1")
if not ts or not sig:
return False
signed_payload = f"{ts}.".encode("utf-8") + body
expected = hmac.new(SIGNING_SECRET, signed_payload, hashlib.sha256).hexdigest()
return hmac.compare_digest(expected, sig) # constant-time, byte-by-byte safeThe t= timestamp is what makes the next mitigation possible. A signature alone with no timestamp is replayable forever.
Reject any event whose signed timestamp is more than 5 minutes from now (in either direction — clock skew goes both ways). This bounds the replay window an attacker has even if they capture a valid signed event off the wire:
import time
REPLAY_WINDOW_SECONDS = 300 # 5 minutes; tune to your clock-skew tolerance
def within_replay_window(ts_str: str) -> bool:
try:
ts = int(ts_str)
except (TypeError, ValueError):
return False
return abs(time.time() - ts) <= REPLAY_WINDOW_SECONDSWire within_replay_window(parts["t"]) immediately after signature verification. A failed window check is a 401 — do not return 200, do not enqueue, do not log the body (the attacker is probing).
SET NX EX 86400 (neutralizes duplicate processing)Every Podium webhook carries an event_id (or equivalent unique identifier — verify against the current schema). Reject any event whose event_id is already in the dedup cache. Use Redis SET key value NX EX 86400 so the check and the claim are atomic; 86400 seconds matches Podium's 24-hour retry ceiling:
import redis.asyncio as redis
REDIS = redis.from_url(os.environ.get("REDIS_URL", "redis://localhost:6379/0"))
async def claim_event(event_id: str) -> bool:
# Returns True if this process is the first to see this event_id.
# Returns False if the event_id is already in the cache (duplicate).
return await REDIS.set(f"podium:evt:{event_id}", "1", nx=True, ex=86400)In the handler:
event = json.loads(raw)
event_id = event["id"]
if not await claim_event(event_id):
return {"status": "duplicate", "event_id": event_id} # 200 — Podium stops retryingReturning 200 on duplicate is correct — Podium has correctly delivered, the receiver has correctly identified it as already processed. The handler is idempotent by construction.
For dev / smoke environments without Redis, fall back to an in-memory set() with a periodic eviction loop. Documented in references/implementation.md.
Wrap every handler invocation in a try/except. On any exception, persist the raw signed payload plus the timestamp plus the signature to the DLQ before letting the exception bubble. The DLQ entry is the recovery anchor — dlq_replay.py can re-POST it to the handler later:
async def safe_dispatch(event: dict, raw: bytes, sig_header: str):
try:
await dispatch(event)
except Exception as e:
await dlq_persist({
"event_id": event.get("id"),
"event_type": event.get("type"),
"raw_body": raw.decode("utf-8", errors="replace"),
"signature_header": sig_header,
"occurred_at": event.get("occurred_at"),
"received_at": time.time(),
"exception": f"{type(e).__name__}: {e}",
})
raise # let FastAPI return 5xx; Podium will retryDLQ backend options (in priority order):
| Backend | When |
|---|---|
Redis list LPUSH podium:dlq + scheduled archiver to S3/GCS | Default for prod |
SQLite file at /var/lib/podium-dlq.sqlite | Single-node deployments, dev |
Append-only JSONL at /var/log/podium-dlq.jsonl | Fallback when nothing else is available — durable, parseable, ugly |
The DLQ is durable independent of the Redis dedup cache. If Redis dies, dedup is degraded but events are still recoverable.
occurred_at (neutralizes reordering)Podium can deliver multiple events in one POST. Within the batch, sort by occurred_at ascending before dispatch. Across batches, do not assume earlier-timestamped events arrived first — guard causally-dependent handlers with an existence check:
async def dispatch_batch(events: list[dict]):
events.sort(key=lambda e: (e.get("occurred_at", 0), e.get("id", "")))
for event in events:
await safe_dispatch_one(event)
async def handle_conversation_deleted(event: dict):
convo_id = event["data"]["conversation_id"]
# Guard: if the create event hasn't been processed yet, defer this delete.
if not await convo_exists(convo_id):
await dlq_persist({
"reason": "out_of_order_delete_before_create",
"event_id": event["id"],
"raw_body": json.dumps(event),
"received_at": time.time(),
})
return
await delete_conversation_locally(convo_id)Sorting within a batch is cheap and correct. Cross-batch ordering is undecidable from the receiver side — the DLQ + replay path is the recovery mechanism when out-of-order delivery violates a precondition.
The single most common implementation bug in webhook receivers is received == expected with ==. Python string == short-circuits on the first differing byte; an attacker measures response latency over a few thousand probes and reconstructs the signature byte by byte.
# WRONG — leaks signature byte-by-byte via timing
if received_sig == expected_sig:
return True
# CORRECT — constant-time over the longer of the two inputs
if hmac.compare_digest(received_sig, expected_sig):
return Truehmac.compare_digest is the only acceptable comparison. The same rule applies to Node (crypto.timingSafeEqual), Go (hmac.Equal), and Rust (subtle::ConstantTimeEq).
| HTTP returned | Internal condition | Caller (Podium) behavior |
|---|---|---|
401 Unauthorized | Signature mismatch, missing header, replay window failed | Podium does NOT retry — log + audit |
400 Bad Request | Body is not parseable JSON post-signature-verify | Podium does NOT retry — investigate Podium-side payload |
200 OK (duplicate) | event_id already in dedup cache | Podium stops retrying — system is idempotent |
200 OK (processed) | Handler dispatched successfully | Podium stops retrying — normal path |
200 OK (deferred) | Out-of-order event written to DLQ; will resolve via replay | Podium stops retrying — recovery is internal |
500 Internal Server Error | Handler raised; DLQ entry persisted | Podium retries with exponential backoff up to 24h |
503 Service Unavailable | Redis dedup unreachable; handler refuses | Podium retries — fail-closed is the safe default |
# Use the CLI bundled with the skill to verify a captured payload + header against the secret.
python3 scripts/signature_verify.py \
--body-file /tmp/captured_webhook_body.json \
--signature-header "t={your-timestamp},v1={your-podium-signature}" \
--secret-env PODIUM_WEBHOOK_SECRET
# exit 0 = valid; exit 1 = signature mismatch; exit 2 = replay window exceededpython3 scripts/dedup_check.py --event-id evt_{your-event-identifier} --redis-url redis://localhost:6379/0
# exit 0 = first sight (would be processed); exit 1 = duplicate (would be rejected)# After a handler bug is fixed, replay DLQ entries through the receiver.
# The replay path goes through the SAME endpoint as Podium, so signature + dedup still apply.
python3 scripts/dlq_replay.py \
--target-url https://your-receiver.example.com/webhooks/podium \
--secret-env PODIUM_WEBHOOK_SECRET \
--batch-size 25 \
--rate-per-sec 10The replay script reuses the original signature header captured at DLQ-persist time — Podium's signing secret is the same secret your replayer uses to compute the header, so no re-signing is required for events captured within the secret's lifetime.
export PODIUM_WEBHOOK_SECRET={your-webhook-secret}
export REDIS_URL=redis://localhost:6379/0 # or unset to use in-memory fallback
uvicorn scripts.webhook_server:app --host 0.0.0.0 --port 8080 --reloadsignature_verify.py) for incident forensics on captured payloadsdedup_check.py) for confirming a specific event was already processeddlq_replay.py) for draining persisted failures after a handler fix.gitignore rules covering the webhook secret + captured payload files© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 10 other files (scripts, references) in skills/.curated/podium-webhook-reliability of jeremylongshore/tons-of-skills-marketplace.
Open the folder on GitHubat commit cfae287
Podium Webhook Reliability next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Podium Webhook Reliability this skilljeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~4k | Automated safety check: Pass | MIT | |
| Rls Patternsbybren-llc/safe-agentic-workflow | 423 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Alert Managementhoangsonww/Claude-Code-Agent-Monitor | 1.1k | — | ~241 | Automated safety check: Pass | MIT | |
| Sec Checkwaynesutton/markdown-site | 627 | — | ~753 | Automated safety check: Pass | MIT | |
| Security Threat Modelmajiayu000/spellbook | 287 | — | ~561 | Automated safety check: Pass | MIT | |
| Security Threat Modelingdevcodex-labs/devcodex | 439 | — | ~771 | Automated safety check: Pass | AGPL-3.0 |
bybren-llc/safe-agentic-workflow
Row Level Security patterns for database operations. An agent skill from bybren-llc/safe-agentic-workflow.
hoangsonww/Claude-Code-Agent-Monitor
Inspect fired CCAM alerts and manage alert rules for token thresholds, event patterns, inactivity, and status duration.
waynesutton/markdown-site
Security review checklist for Convex functions, auth logic, public queries, admin routes, webhooks, uploads, and AI-generated code.
majiayu000/spellbook
Threat-model product features, APIs, data flows, secrets, permissions, supply-chain changes, auth boundaries, and risky code paths before or during implementation.
devcodex-labs/devcodex
安全威胁建模专家 Owner — 当任务涉及权限、认证、授权、输入输出信任边界、密钥策略、审计、攻击面、Webhook/OAuth、敏感操作或用户要求安全专家视角时使用;要求识别滥用路径并绑定缓解验证。
novuhq/novu
Design notification workflows the Novu way — choose channels, set severity, decide when a workflow is critical, configure digests, and route based on subscriber state.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
jeremylongshore/tons-of-skills-marketplace
Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.
jeremylongshore/tons-of-skills-marketplace
Execute proactive auto-loading: automatically detects and loads agents.md files.
jeremylongshore/tons-of-skills-marketplace
Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.
jeremylongshore/tons-of-skills-marketplace
Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.
Categories
Operate a Podium webhook receiver that survives the delivery-side failures — forged events without signature verification, replay attacks against a stateless handler, duplicate processing from…. Podium Webhook Reliability is an agent skill from jeremylongshore/tons-of-skills-marketplace. Operate a Podium webhook receiver that survives the delivery-side failures — forged events without signature verification, replay attacks against a stateless handler, duplicate processing from Podium's 24h retry policy, lost events with no dead-letter queue, out-of-order batch deliveries, and timing-attack-vulnerable HMAC compares.
Podium Webhook Reliability fits situations like: building a webhook endpoint for call transcripts; conversation lifecycle; review notifications; hardening an existing handler that processes events twice.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-webhook-reliability -a claude-code`. Or copy the skill folder (skills/.curated/podium-webhook-reliability in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/podium-webhook-reliability in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-webhook-reliability -a codex`. Or copy the skill folder (skills/.curated/podium-webhook-reliability in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/podium-webhook-reliability in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill podium-webhook-reliability -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/podium-webhook-reliability, .gemini/skills/podium-webhook-reliability, .github/skills/podium-webhook-reliability and .opencode/skills/podium-webhook-reliability in your project.
Going by SKILL.md and its folder, Podium Webhook Reliability needs Python for the scripts in its folder, the command-line tools its instructions call (python3 and uvicorn) and credentials named PODIUM_WEBHOOK_SECRET and SIGNING_SECRET. Our summary lists: Python 3; A credential in SIGNING_SECRET; A credential in PODIUM_WEBHOOK_SECRET. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(curl:*), Bash(jq:*), Bash(python3:*), Bash(redis-cli:*), Grep. Compatibility (from SKILL.md): Designed for Claude Code.
SKILL.md names 1 domain. As links in the text: docs.podium.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Podium Webhook Reliability is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Podium Webhook Reliability: Rls Patterns (bybren-llc/safe-agentic-workflow, 423 stars), Alert Management (hoangsonww/Claude-Code-Agent-Monitor, 1.1k stars), Sec Check (waynesutton/markdown-site, 627 stars) and Security Threat Model (majiayu000/spellbook, 287 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.
Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.