Agent skill

Webhook Subscriptions

by mateaix in mateaix/mateclaw

Webhook subscriptions: event-driven agent runs. An agent skill from mateaix/mateclaw.

Apache-2.0Auto-check: notesBackend & APIs

Install Webhook Subscriptions

skills CLI
$ npx skills add mateaix/mateclaw --skill webhook-subscriptions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mateaix/mateclaw webhook-subscriptions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mateaix/mateclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/mateclaw-server/src/main/resources/skills/webhook-subscriptions .claude/skills/webhook-subscriptions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
webhook-subscriptions
GitHub stars
1.1k
Token cost
~1.7k tokens
SKILL.md length
553 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

Webhook subscriptions: event-driven agent runs. An agent skill from mateaix/mateclaw.

  • Works in 4 steps: the agent webhook subscribe writes to… → The webhook adapter hot-reloads this… → When a POST arrives matching a route,… → …
  • Tasks that involve Webhooks
  • SKILL.md covers Setup (Required First), Commands, Prompt Templates and Common Patterns, plus 3 more sections
  • Calls curl; needs WEBHOOK_SECRET

What it does

Webhook Subscriptions is an agent skill from mateaix/mateclaw. Webhook subscriptions: event-driven agent runs.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Webhooks. It works with GitHub and Stripe. The repository describes itself as: 🤖 MateClaw — Your second brain with Multi-Agent Orchestration, MCP Protocol, Skills & Memory, Dream, and Multi-Channel Support. Built on Spring AI Alibaba. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Webhooks

Example prompts

  • “/webhook-subscriptions”

Requirements

  • A credential in WEBHOOK_SECRET

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. the agent webhook subscribe writes to ~/.mateclaw/webhook_subscriptions.json
  2. The webhook adapter hot-reloads this file on each incoming request (mtime-gated, negligible overhead)
  3. When a POST arrives matching a route, the adapter formats the prompt and triggers an agent run
  4. The agent's response is delivered to the configured target (Telegram, Discord, GitHub comment, etc.)

What it can do on your machine

Read from SKILL.md and the folder at commit 3b5f7de. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • WEBHOOK_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Webhook Subscriptions loads about 1.7k tokens when it runs. Until then it costs about 17 tokens; SKILL.md has 553 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~17
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:46
    Add to `~/.mateclaw/.env`:

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mateaix/mateclaw at commit 3b5f7de, republished under its Apache-2.0 licence (© mateaix). 553 words, ~1,712 tokens.

Download SKILL.mdSave it as .claude/skills/webhook-subscriptions/SKILL.md (or your agent's skills folder).
name
webhook-subscriptions
description
Webhook subscriptions: event-driven agent runs.
version
1.1.0
tags
webhook, events, automation, integrations, notifications, push
author
ported

Webhook Subscriptions

Create dynamic webhook subscriptions so external services (GitHub, GitLab, Stripe, CI/CD, IoT sensors, monitoring tools) can trigger the agent agent runs by POSTing events to a URL.

Setup (Required First)

The webhook platform must be enabled before subscriptions can be created. Check with:

bash
the agent webhook list

If it says "Webhook platform is not enabled", set it up:

Option 1: Setup wizard
bash
the agent gateway setup

Follow the prompts to enable webhooks, set the port, and set a global HMAC secret.

Option 2: Manual config

Add to ~/.mateclaw/config.yaml:

yaml
platforms:
  webhook:
    enabled: true
    extra:
      host: "0.0.0.0"
      port: 8644
      secret: "generate-a-strong-secret-here"
Option 3: Environment variables

Add to ~/.mateclaw/.env:

bash
WEBHOOK_ENABLED=true
WEBHOOK_PORT=8644
WEBHOOK_SECRET=generate-a-strong-secret-here

After configuration, start (or restart) the gateway:

bash
the agent gateway run
# Or if using systemd:
systemctl --user restart the agent-gateway

Verify it's running:

bash
curl http://localhost:8644/health

Commands

All management is via the the agent webhook CLI command:

Create a subscription
bash
the agent webhook subscribe <name> \
  --prompt "Prompt template with {payload.fields}" \
  --events "event1,event2" \
  --description "What this does" \
  --skills "skill1,skill2" \
  --deliver telegram \
  --deliver-chat-id "12345" \
  --secret "optional-custom-secret"

Returns the webhook URL and HMAC secret. The user configures their service to POST to that URL.

List subscriptions
bash
the agent webhook list
Remove a subscription
bash
the agent webhook remove <name>
Test a subscription
bash
the agent webhook test <name>
the agent webhook test <name> --payload '{"key": "value"}'

Prompt Templates

Prompts support {dot.notation} for accessing nested payload fields:

  • {issue.title} — GitHub issue title
  • {pull_request.user.login} — PR author
  • {data.object.amount} — Stripe payment amount
  • {sensor.temperature} — IoT sensor reading

If no prompt is specified, the full JSON payload is dumped into the agent prompt.

Common Patterns

GitHub: new issues
bash
the agent webhook subscribe github-issues \
  --events "issues" \
  --prompt "New GitHub issue #{issue.number}: {issue.title}\n\nAction: {action}\nAuthor: {issue.user.login}\nBody:\n{issue.body}\n\nPlease triage this issue." \
  --deliver telegram \
  --deliver-chat-id "-100123456789"

Then in GitHub repo Settings → Webhooks → Add webhook:

  • Payload URL: the returned webhook_url
  • Content type: application/json
  • Secret: the returned secret
  • Events: "Issues"
GitHub: PR reviews
bash
the agent webhook subscribe github-prs \
  --events "pull_request" \
  --prompt "PR #{pull_request.number} {action}: {pull_request.title}\nBy: {pull_request.user.login}\nBranch: {pull_request.head.ref}\n\n{pull_request.body}" \
  --skills "github-code-review" \
  --deliver github_comment
Stripe: payment events
bash
the agent webhook subscribe stripe-payments \
  --events "payment_intent.succeeded,payment_intent.payment_failed" \
  --prompt "Payment {data.object.status}: {data.object.amount} cents from {data.object.receipt_email}" \
  --deliver telegram \
  --deliver-chat-id "-100123456789"
CI/CD: build notifications
bash
the agent webhook subscribe ci-builds \
  --events "pipeline" \
  --prompt "Build {object_attributes.status} on {project.name} branch {object_attributes.ref}\nCommit: {commit.message}" \
  --deliver discord \
  --deliver-chat-id "1234567890"
Generic monitoring alert
bash
the agent webhook subscribe alerts \
  --prompt "Alert: {alert.name}\nSeverity: {alert.severity}\nMessage: {alert.message}\n\nPlease investigate and suggest remediation." \
  --deliver origin
Direct delivery (no agent, zero LLM cost)

For use cases where you just want to push a notification through to a user's chat — no reasoning, no agent loop — add --deliver-only. The rendered --prompt template becomes the literal message body and is dispatched directly to the target adapter.

Use this for:

  • External service push notifications (Supabase/Firebase webhooks → Telegram)
  • Monitoring alerts that should forward verbatim
  • Inter-agent pings where one agent is telling another agent's user something
  • Any webhook where an LLM round trip would be wasted effort
bash
the agent webhook subscribe antenna-matches \
  --deliver telegram \
  --deliver-chat-id "123456789" \
  --deliver-only \
  --prompt "🎉 New match: {match.user_name} matched with you!" \
  --description "Antenna match notifications"

The POST returns 200 OK on successful delivery, 502 on target failure — so upstream services can retry intelligently. HMAC auth, rate limits, and idempotency still apply.

Requires --deliver to be a real target (telegram, discord, slack, github_comment, etc.) — --deliver log is rejected because log-only direct delivery is pointless.

Show full SKILL.md (203 more words)Show less

Security

  • Each subscription gets an auto-generated HMAC-SHA256 secret (or provide your own with --secret)
  • The webhook adapter validates signatures on every incoming POST
  • Static routes from config.yaml cannot be overwritten by dynamic subscriptions
  • Subscriptions persist to ~/.mateclaw/webhook_subscriptions.json

How It Works

  1. the agent webhook subscribe writes to ~/.mateclaw/webhook_subscriptions.json
  2. The webhook adapter hot-reloads this file on each incoming request (mtime-gated, negligible overhead)
  3. When a POST arrives matching a route, the adapter formats the prompt and triggers an agent run
  4. The agent's response is delivered to the configured target (Telegram, Discord, GitHub comment, etc.)

Troubleshooting

If webhooks aren't working:

  1. Is the gateway running? Check with systemctl --user status the agent-gateway or ps aux | grep gateway
  2. Is the webhook server listening? curl http://localhost:8644/health should return {"status": "ok"}
  3. Check gateway logs: grep webhook ~/.mateclaw/logs/gateway.log | tail -20
  4. Signature mismatch? Verify the secret in your service matches the one from the agent webhook list. GitHub sends X-Hub-Signature-256, GitLab sends X-Gitlab-Token.
  5. Firewall/NAT? The webhook URL must be reachable from the service. For local development, use a tunnel (ngrok, cloudflared).
  6. Wrong event type? Check --events filter matches what the service sends. Use the agent webhook test <name> to verify the route works.

© mateaix, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in mateclaw-server/src/main/resources/skills/webhook-subscriptions of mateaix/mateclaw.

Open the folder on GitHubat commit 3b5f7de

Compare with similar skills

Webhook Subscriptions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Webhook Subscriptions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Webhook Subscriptions this skillmateaix/mateclaw1.1k—~1.7kAutomated safety check: NotesApache-2.0
Webhook SubscriptionsTommy-yw/RunbookHermes5461 repos~1.7kAutomated safety check: NotesMIT
Production Auditsickn33/agentic-awesome-skills47k1 repos~2.7kAutomated safety check: PassMIT
Emulate Seedyonatangross/orchestkit288—~4.5kAutomated safety check: PassMIT
Webhook SubscriptionsRedWoodOG/Hermes-Desktop177—~1.4kAutomated safety check: NotesNone
Ade Webhooksarul28/ADE113—~2.1kAutomated safety check: PassAGPL-3.0

Similar skills

  • Webhook Subscriptions

    Tommy-yw/RunbookHermes

    Create and manage webhook subscriptions for event-driven agent activation, or for direct push notifications (zero LLM cost).

    546 GitHub starsUsed in 1 repo~1.7k tokens
    Backend & APIsAuto-check: notes
  • Production Audit

    sickn33/agentic-awesome-skills

    Audit a shipped repo for production-readiness gaps across RLS, webhooks, secrets, grants, Stripe idempotency, mobile UX, and deployment health.

    47k GitHub starsUsed in 1 repo~2.7k tokens
    Backend & APIsAuto-check passed
  • Emulate Seed

    yonatangross/orchestkit

    Generate emulate seed configs for stateful API emulation. An agent skill from yonatangross/orchestkit.

    288 GitHub stars~4.5k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Webhook Subscriptions

    RedWoodOG/Hermes-Desktop

    Create and manage webhook subscriptions for event-driven agent activation.

    177 GitHub stars~1.4k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Ade Webhooks

    arul28/ADE

    A skill your agent uses when someone wants an agent to run whenever something happens in another service — a GitHub issue or PR, a Stripe payment, a Linear issue, a Sentry error, a failed deploy…

    113 GitHub stars~2.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Trigger Registry

    evolution-foundation/evo-nexus

    Create, manage, and test reactive triggers (webhook & event-based).

    544 GitHub stars~1.4k tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed

More from mateaix/mateclaw

All 17 skills in this repo
  • Pixel Art

    mateaix/mateclaw

    Pixel art w/ era palettes (NES, Game Boy, PICO-8). An agent skill from mateaix/mateclaw.

    1.1k GitHub starsUsed in 5 repos~1.8k tokens
    Auto-check passed
  • DOCX

    mateaix/mateclaw

    A skill your agent uses whenever the user wants to create, read, edit, or manipulate Word documents (.docx files).

    1.1k GitHub stars~4.1k tokensUpdated 2 days ago
    Auto-check passed
  • XLSX

    mateaix/mateclaw

    Use this skill any time a spreadsheet file is the primary input or output.

    1.1k GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Execute plans via delegatetask subagents (2-stage review). An agent skill from mateaix/mateclaw.

    1.1k GitHub starsUsed in 3 repos~2.6k tokens
    Auto-check passed
  • Ideation

    mateaix/mateclaw

    Generate project ideas via creative constraints. An agent skill from mateaix/mateclaw.

    1.1k GitHub starsUsed in 2 repos~1.5k tokens
    Auto-check passed
  • Architecture Diagram

    mateaix/mateclaw

    Dark-themed SVG architecture/cloud/infra diagrams as HTML. An agent skill from mateaix/mateclaw.

    1.1k GitHub starsUsed in 5 repos~1.7k tokens
    Auto-check passed

Works with

Categories

Questions about Webhook Subscriptions

What does Webhook Subscriptions do?

Webhook subscriptions: event-driven agent runs. An agent skill from mateaix/mateclaw. Webhook Subscriptions is an agent skill from mateaix/mateclaw. Webhook subscriptions: event-driven agent runs.

When should I use Webhook Subscriptions?

Webhook Subscriptions fits situations like: tasks that involve Webhooks.

How do I install Webhook Subscriptions in Claude Code?

Run `npx skills add mateaix/mateclaw --skill webhook-subscriptions -a claude-code`. Or copy the skill folder (mateclaw-server/src/main/resources/skills/webhook-subscriptions in mateaix/mateclaw) into .claude/skills/webhook-subscriptions in your project. Claude Code loads it when a task matches its description.

How do I install Webhook Subscriptions in Codex?

Run `npx skills add mateaix/mateclaw --skill webhook-subscriptions -a codex`. Or copy the skill folder (mateclaw-server/src/main/resources/skills/webhook-subscriptions in mateaix/mateclaw) into .agents/skills/webhook-subscriptions in your project. Codex loads it when a task matches its description.

Can I use Webhook Subscriptions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mateaix/mateclaw --skill webhook-subscriptions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/webhook-subscriptions, .gemini/skills/webhook-subscriptions, .github/skills/webhook-subscriptions and .opencode/skills/webhook-subscriptions in your project.

What does Webhook Subscriptions need to run?

Going by SKILL.md and its folder, Webhook Subscriptions needs the command-line tools its instructions call (curl) and credentials named WEBHOOK_SECRET. Our summary lists: A credential in WEBHOOK_SECRET.

Does Webhook Subscriptions access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Webhook Subscriptions safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Webhook Subscriptions use?

Webhook Subscriptions is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Webhook Subscriptions use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Webhook Subscriptions?

Skills that share tags, products or a category with Webhook Subscriptions: Webhook Subscriptions (Tommy-yw/RunbookHermes, 546 stars), Production Audit (sickn33/agentic-awesome-skills, 47k stars), Emulate Seed (yonatangross/orchestkit, 288 stars) and Webhook Subscriptions (RedWoodOG/Hermes-Desktop, 177 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Webhook Subscriptions?

mateaix (a GitHub user) maintains it in mateaix/mateclaw, which has 1,147 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 5, 2026.

Source: mateaix/mateclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.