Webhook Subscriptions
Tommy-yw/RunbookHermes
Create and manage webhook subscriptions for event-driven agent activation, or for direct push notifications (zero LLM cost).
Audit a shipped repo for production-readiness gaps across RLS, webhooks, secrets, grants, Stripe idempotency, mobile UX, and deployment health.
$ npx skills add sickn33/agentic-awesome-skills --skill production-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install sickn33/agentic-awesome-skills production-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/production-audit .claude/skills/production-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "production-audit" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/production-audit into .claude/skills/production-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "production-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/production-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add sickn33/agentic-awesome-skills --skill production-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install sickn33/agentic-awesome-skills production-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/production-audit .agents/skills/production-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "production-audit" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/production-audit into .agents/skills/production-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "production-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill production-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install sickn33/agentic-awesome-skills production-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/production-audit .cursor/skills/production-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "production-audit" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/production-audit into .cursor/skills/production-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "production-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/sickn33/agentic-awesome-skills.git --path skills/production-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add sickn33/agentic-awesome-skills --skill production-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install sickn33/agentic-awesome-skills production-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/production-audit .gemini/skills/production-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "production-audit" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/production-audit into .gemini/skills/production-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "production-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install sickn33/agentic-awesome-skills production-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add sickn33/agentic-awesome-skills --skill production-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/production-audit .github/skills/production-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "production-audit" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/production-audit into .github/skills/production-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "production-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill production-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install sickn33/agentic-awesome-skills production-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/production-audit .opencode/skills/production-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "production-audit" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/production-audit into .opencode/skills/production-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "production-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
production-auditAudit a shipped repo for production-readiness gaps across RLS, webhooks, secrets, grants, Stripe idempotency, mobile UX, and deployment health.
Production Audit is an agent skill from sickn33/agentic-awesome-skills. Audit a shipped repo for production-readiness gaps across RLS, webhooks, secrets, grants, Stripe idempotency, mobile UX, and deployment health.
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Webhooks and Mobile UI design. It works with Stripe and GitHub. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 680176d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxjqgitFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.commit.showAlso links to:
github.comcommit.showskills.shFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Production Audit loads about 2.7k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 1,221 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from sickn33/agentic-awesome-skills at commit 680176d, republished under its MIT licence (© sickn33). 1,221 words, ~2,713 tokens.
.claude/skills/production-audit/SKILL.md (or your agent's skills folder).A skill that runs an external audit on a shipped repo's deployed state — live URL, GitHub signals, secrets exposure, RLS gaps, webhook idempotency, indexes, observability, prompt injection, and ten other failure modes that AI-assisted projects routinely miss.
This is complementary to in-session security skills (security-review, OWASP-style, VibeSec, Trail of Bits). Those scan the editor buffer at write-time. This scans the deployed product after you commit. Different timing, different inputs, different findings. Run both for serious launches.
The skill wraps the commit.show audit engine via the public CLI (npx commitshow@0.3.23 audit . --json). Stable JSON envelope (schema_version: "1", additive-only). Writes a .commitshow/audit.{md,json} sidecar so future agent sessions can read prior state without re-running the engine.
main (helpful as a pre-deploy gate).git log shows >20 commits since the last .commitshow/audit.md was written.security-review / OWASP-style for line-level patterns. This skill is for post-merge / pre-ship review..commitshow/audit.json already exists and is < 1 hour old, read that instead of re-running. Audit is rate-limited (anonymous: 20/IP/day · 5/repo/day · 2000/day global).not_found error.From the repo root. The CLI is pinned to an exact reviewed version so future npm releases are not selected silently. Because npx downloads and runs npm package code locally with the current user's permissions, run it only after the user explicitly approves this external execution and only in a repository where local files and environment variables are safe for that process to access. The sidecar directory is created up-front, and stderr is split off so install/deprecation warnings can't corrupt the JSON envelope:
mkdir -p .commitshow
npx commitshow@0.3.23 audit . --json \
> .commitshow/audit.json \
2> .commitshow/audit.stderr.logThis also writes a human-readable .commitshow/audit.md next to it. Subsequent invocations should diff against the prior audit.json if it exists, so you can lead with "+5 since yesterday's audit" instead of just an absolute number.
If the user pointed at a remote URL instead of ., swap . for the URL — keep the same mkdir -p + version pin + stderr split:
mkdir -p .commitshow
npx commitshow@0.3.23 audit github.com/owner/repo --json \
> .commitshow/audit.json \
2> .commitshow/audit.stderr.logThe JSON envelope is stable (schema_version: "1", additive-only). Read these fields:
| Field | Meaning |
|---|---|
score.total | 0-100 production-readiness score |
score.delta_since_last | change vs. parent snapshot · positive = improving |
score.band | strong (80+) · mid (60-79) · early (<60) |
concerns[] | top issues, ordered by impact · each has axis + bullet |
strengths[] | top 3 things that work · for context only |
standing | optional · only when the project is auditioning on commit.show |
snapshot.created_at / trigger_type | when the audit ran |
Concerns are sorted by decision-impact, not severity. Position 1 is the bullet to lead with.
Lead with score + trajectory in one sentence, then the top concerns. Do not dump the full JSON. Format:
Score: 82/100 (+5 since yesterday) · band: strong
Top concerns:
↓ [Security] No API rate limiting on /auth — IP cap missing
↓ [Infrastructure] webhook handler at api/stripe.ts — signature verified, but no
idempotency-key check (replay attack window open)
Want me to fix the webhook idempotency gap first?Rules:
concerns[].bullet — the audit engine already wrote action-oriented copy.score.delta_since_last is negative or null, lead with the absolute score only.For the chosen concern:
After applying a fix, suggest re-running with --refresh (same canonical form as Step 1, so audit.json stays the source of truth for delta calculations):
mkdir -p .commitshow
npx commitshow@0.3.23 audit . --json --refresh \
> .commitshow/audit.json \
2> .commitshow/audit.stderr.logmkdir -p .commitshow
npx commitshow@0.3.23 audit . --json \
> .commitshow/audit.json \
2> .commitshow/audit.stderr.logThen surface:
Score: 67/100 · band: mid
Top concerns:
↓ [Security] members table uses column-level GRANT but paid_audits_credit
column lacks SELECT grant — silent 42501 on every read
↓ [Infrastructure] stripe.checkout.sessions.create called without
idempotencyKey — duplicate-charge surface
Want me to fix the column GRANT first? Single SQL line.User: "show me where the webhook idempotency gap is"
cat .commitshow/audit.json | jq '.concerns[] | select(.axis=="Infrastructure")'Find the file path in the bullet, read it, confirm the gap matches.
concerns[].bullet — they're already action-oriented.commitshow/audit.json before re-running (within 1h)--refresh after the user merges a fix so the next audit reflects it*.supabase.co, the API call fails. There is no offline mode — the audit relies on the public engine.--refresh force-bypasses cache (counts against rate limits).npx commitshow@0.3.23 audit ..., which downloads and runs that exact npm package version locally, then calls the public API at https://api.commit.show (proxied to Supabase Edge Functions). Do not replace the exact version with latest or a semver range during normal use..commitshow/audit.{md,json} in the current working directory. These files are safe to commit (no secrets) but conventionally gitignored as transient artifacts.Problem: Audit returns not_found for a private repo
Solution: The engine pulls public GitHub signals only. Either make the repo public or use --no-network for local-only deterministic checks.
Problem: Rate limit hit (429)
Solution: Wait until next day (limits reset 00:00 UTC) or sign in at commit.show for higher per-repo caps.
Problem: Score seems too low for a polished library / CLI Solution: The engine biases toward app form. CLI / library / scaffold gets a partial substitute score capped around 45/50 on the audit pillar. Calibration acknowledged trade-off.
Problem: concerns[] is empty after re-running
Solution: Re-audit may have hit cache. Use --refresh to force-bypass.
@security-review — In-session line-level security patterns. Run alongside this skill, not in place of.@vibesec — Editor-buffer security review for vibe-coded projects. Different lens.@owasp-security — OWASP Top 10 coverage during coding. Companion.@trail-of-bits-skills — CodeQL / Semgrep static analysis. Different layer.schema_version: "1" · additive-only changes.https://api.commit.show/audit?repo=...&format=json© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/production-audit of sickn33/agentic-awesome-skills.
Open the folder on GitHubat commit 680176d
We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.
Production Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Production Audit this skillsickn33/agentic-awesome-skills | 47k | 1 repos | ~2.7k | Automated safety check: Pass | MIT | |
| Webhook SubscriptionsTommy-yw/RunbookHermes | 546 | 1 repos | ~1.7k | Automated safety check: Notes | MIT | |
| Webhook Subscriptionsmateaix/mateclaw | 1.1k | — | ~1.7k | Automated safety check: Notes | Apache-2.0 | |
| Emulate Seedyonatangross/orchestkit | 290 | — | ~4.5k | Automated safety check: Pass | MIT | |
| Webhook SubscriptionsRedWoodOG/Hermes-Desktop | 177 | — | ~1.4k | Automated safety check: Notes | None | |
| Ade Webhooksarul28/ADE | 114 | — | ~2.1k | Automated safety check: Pass | AGPL-3.0 |
Tommy-yw/RunbookHermes
Create and manage webhook subscriptions for event-driven agent activation, or for direct push notifications (zero LLM cost).
mateaix/mateclaw
Webhook subscriptions: event-driven agent runs. An agent skill from mateaix/mateclaw.
yonatangross/orchestkit
Generate emulate seed configs for stateful API emulation. An agent skill from yonatangross/orchestkit.
RedWoodOG/Hermes-Desktop
Create and manage webhook subscriptions for event-driven agent activation.
arul28/ADE
A skill your agent uses when someone wants an agent to run whenever something happens in another service — a GitHub issue or PR, a Stripe payment, a Linear issue, a Sentry error, a failed deploy…
evolution-foundation/evo-nexus
Create, manage, and test reactive triggers (webhook & event-based).
sickn33/agentic-awesome-skills
Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.
sickn33/agentic-awesome-skills
Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.
sickn33/agentic-awesome-skills
Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.
sickn33/agentic-awesome-skills
Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.
sickn33/agentic-awesome-skills
Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.
sickn33/agentic-awesome-skills
Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.
Categories
Audit a shipped repo for production-readiness gaps across RLS, webhooks, secrets, grants, Stripe idempotency, mobile UX, and deployment health. Production Audit is an agent skill from sickn33/agentic-awesome-skills. Audit a shipped repo for production-readiness gaps across RLS, webhooks, secrets, grants, Stripe idempotency, mobile UX, and deployment health.
Production Audit fits situations like: tasks that involve Webhooks; tasks that involve Mobile UI design.
Run `npx skills add sickn33/agentic-awesome-skills --skill production-audit -a claude-code`. Or copy the skill folder (skills/production-audit in sickn33/agentic-awesome-skills) into .claude/skills/production-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add sickn33/agentic-awesome-skills --skill production-audit -a codex`. Or copy the skill folder (skills/production-audit in sickn33/agentic-awesome-skills) into .agents/skills/production-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill production-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/production-audit, .gemini/skills/production-audit, .github/skills/production-audit and .opencode/skills/production-audit in your project.
Going by SKILL.md and its folder, Production Audit needs the command-line tools its instructions call (npx, jq and git). Our summary lists: Node.js.
SKILL.md names 4 domains. In commands or code: api.commit.show; the agent is likely to contact it when it follows the instructions. As links in the text: github.com, commit.show and skills.sh. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Production Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Production Audit: Webhook Subscriptions (Tommy-yw/RunbookHermes, 546 stars), Webhook Subscriptions (mateaix/mateclaw, 1.1k stars), Emulate Seed (yonatangross/orchestkit, 290 stars) and Webhook Subscriptions (RedWoodOG/Hermes-Desktop, 177 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,379 GitHub stars. The repository holds 1,493 skills in this directory. The repository was last updated on October 9, 2026.
Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.