Agent skill

Validate Trigger

by simstudioai in simstudioai/sim

Validate an existing Sim webhook trigger against provider API docs and repository conventions

Apache-2.0Auto-check passedBackend & APIs

Install Validate Trigger

skills CLI
$ npx skills add simstudioai/sim --skill validate-trigger -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install simstudioai/sim validate-trigger --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/validate-trigger .claude/skills/validate-trigger && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
validate-trigger
GitHub stars
30k
Token cost
~3.1k tokens
SKILL.md length
1,374 words
Files
1
Skills in repo
40
Repo updated
First seen
Licence
Apache-2.0

At a glance

Validate an existing Sim webhook trigger against provider API docs and repository conventions

  • Works in 8 steps: Gather All Files → Pull API Documentation → Validate Trigger Definitions → …
  • Against provider API docs and repository conventions
  • SKILL.md covers Your Task, Step 1: Gather All Files, Step 2: Pull API Documentation and Step 3: Validate Trigger…, plus 6 more sections
  • Calls bun

What it does

Validate Trigger is an agent skill from simstudioai/sim. Validate an existing Sim webhook trigger against provider API docs and repository conventions

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Webhooks and Technical documentation. The repository describes itself as: Sim is the collaborative workspace to build, deploy, and monitor AI agents and workflows. Used by 100,000+ builders. The licence is Apache-2.0.

When your agent uses it

  • Against provider API docs and repository conventions
  • Tasks that involve Webhooks
  • Tasks that involve Technical documentation

Example prompts

  • “/validate-trigger”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Gather All Files
  2. Pull API Documentation
  3. Validate Trigger Definitions
  4. Validate Provider Handler
  5. Validate Automatic Subscription Lifecycle
  6. Validate Registration and Block Wiring
  7. Validate Security
  8. Report and Fix

What it can do on your machine

Read from SKILL.md and the folder at commit 546d4e7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bun

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Validate Trigger loads about 3.1k tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 1,374 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~28
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from simstudioai/sim at commit 546d4e7, republished under its Apache-2.0 licence (© simstudioai). 1,374 words, ~3,069 tokens.

Download SKILL.mdSave it as .claude/skills/validate-trigger/SKILL.md (or your agent's skills folder).
name
validate-trigger
description
Validate an existing Sim webhook trigger against provider API docs and repository conventions
argument-hint
<service-name> [api-docs-url]

Validate Trigger

You are an expert auditor for Sim webhook triggers. Your job is to validate that an existing trigger implementation is correct, complete, secure, and aligned across all layers.

Your Task

  1. Read the service's webhook/API documentation (via WebFetch)
  2. Read every trigger file, provider handler, and registry entry
  3. Cross-reference against the API docs and Sim conventions
  4. Report all issues grouped by severity (critical, warning, suggestion)
  5. Fix all issues after reporting them

Step 1: Gather All Files

Read every file for the trigger — do not skip any:

apps/sim/triggers/{service}/           # All trigger files, utils.ts, index.ts
apps/sim/lib/webhooks/providers/{service}.ts  # Provider handler (if exists)
apps/sim/lib/webhooks/providers/registry.ts   # Handler registry
apps/sim/triggers/registry.ts                 # Trigger registry
apps/sim/blocks/blocks/{service}.ts           # Block definition (trigger wiring)

Also read for reference:

apps/sim/lib/webhooks/providers/types.ts            # WebhookProviderHandler interface
apps/sim/lib/webhooks/providers/utils.ts            # Shared helpers (createHmacVerifier, etc.)
apps/sim/lib/webhooks/provider-subscription-utils.ts    # Subscription helpers
apps/sim/lib/webhooks/processor.ts                  # Central webhook processor

If trigger sub-blocks use a selectorKey, also apply the validate-selector skill and read the key's browser-safe manifest entry, shared active-value context builder, server attachment, and provider listing primitive.

Step 2: Pull API Documentation

Fetch the service's official webhook documentation. This is the source of truth for:

  • Webhook event types and payload shapes
  • Signature/auth verification method (HMAC algorithm, header names, secret format)
  • Challenge/verification handshake requirements
  • Webhook subscription API (create/delete endpoints, if applicable)
  • Retry behavior and delivery guarantees
Hard Rule: No Guessed Webhook Payload Schemas

If the official docs do not clearly show the webhook payload JSON for an event, you MUST tell the user instead of guessing.

  • Do NOT invent payload field names
  • Do NOT infer nested payload paths without evidence
  • Do NOT treat likely event shapes as verified
  • Do NOT accept formatInput mappings that are not backed by docs or live payloads

If a payload schema is unknown, validation must explicitly recommend:

  1. sample webhook payloads,
  2. a live test webhook source, or
  3. trimming the trigger to only documented outputs.

Step 3: Validate Trigger Definitions

utils.ts
  • {service}TriggerOptions lists all trigger IDs accurately
  • {service}SetupInstructions provides clear, correct steps for the service
  • build{Service}ExtraFields includes relevant filter/config fields with correct condition
  • Output builders expose all meaningful fields from the webhook payload
  • Output builders do NOT use optional: true or items (tool-output-only features)
  • Nested output objects correctly model the payload structure
Trigger Files
  • Exactly one primary trigger has includeDropdown: true
  • All secondary triggers do NOT have includeDropdown
  • Webhook triggers use buildTriggerSubBlocks (directly or through a service wrapper) unless they deliberately keep a custom layout, as triggers/airtable/webhook.ts does; polling triggers (polling: true) declare subBlocks manually
  • Every trigger's id matches the convention {service}_{event_name}
  • Every trigger's provider matches the service name used in the handler registry
  • index.ts barrel exports all triggers
  • Every remote selectorKey is present in apps/sim/lib/selectors/manifest.ts and has exactly one server attachment
  • Trigger-mode dependsOn fields project only active canonical values; exact {{KEY}} references stay unresolved in the browser
  • Trigger selectors use the shared selectors.execute transport, with no client provider module, browser token request, or selector-only provider route
Trigger ↔ Provider Alignment (CRITICAL)
  • Every trigger ID referenced in matchEvent logic exists in {service}TriggerOptions
  • Event matching logic in the provider correctly maps trigger IDs to service event types
  • Event matching logic in is{Service}EventMatch (if exists) correctly identifies events per the API docs

Step 4: Validate Provider Handler

Auth Verification
  • verifyAuth correctly validates webhook signatures per the service's documentation
  • HMAC algorithm matches (SHA-1, SHA-256, SHA-512)
  • Signature header name matches the API docs exactly
  • Signature format is handled (raw hex, sha256= prefix, base64, etc.)
  • Uses safeCompare for timing-safe comparison (no ===)
  • If webhookSecret is required, handler rejects when it's missing (fail-closed)
  • Signature is computed over raw body (not parsed JSON)
Event Matching
  • matchEvent returns true to run, or false / a NextResponse to skip with a custom body
  • Challenge/verification events are excluded from matching (e.g., endpoint.url_validation)
  • When triggerId is a generic webhook ID, all events pass through
  • When triggerId is specific, only matching events pass
  • Event matching logic uses dynamic await import() for trigger utils (avoids circular deps)
formatInput (CRITICAL)
  • Every key in the formatInput return matches a key in the trigger outputs schema
  • Every key in the trigger outputs schema is populated by formatInput
  • No extra undeclared keys that users can't discover in the UI
  • No wrapper objects (webhook: { ... }, {service}: { ... })
  • Nested output paths exist at the correct depth (e.g., resource.id actually has resource: { id: ... })
  • null is used for missing optional fields (not empty strings or empty objects)
  • Returns { input: { ... } } — not a bare object
  • Every mapped payload field is backed by official docs or live-verified webhook payloads
Idempotency
  • extractIdempotencyId returns a stable, unique key per delivery
  • Uses provider-specific delivery IDs when available (e.g., X-Request-Id, Linear-Delivery, svix-id)
  • Falls back to content-based ID (e.g., ${type}:${id}) when no delivery header exists
  • Does NOT include timestamps in the idempotency key (would break dedup on retries)
Challenge Handling (if applicable)
  • handleChallenge correctly implements the service's URL verification handshake
  • Returns the expected response format per the API docs
  • Env-backed secrets are resolved via resolveEnvVarsInObject if needed

Step 5: Validate Automatic Subscription Lifecycle

If the service supports programmatic webhook creation:

createSubscription
  • Calls the correct API endpoint to create a webhook
  • Sends the correct event types/filters
  • Passes the notification URL from getNotificationUrl(ctx.webhook)
  • Returns { providerConfigUpdates: { externalId } } with the external webhook ID
  • Throws on failure (orchestration handles rollback)
  • Provides user-friendly error messages (401 → "Invalid API Key", etc.)
Show full SKILL.md (553 more words)Show less
deleteSubscription
  • Calls the correct API endpoint to delete the webhook
  • Handles 404 gracefully (webhook already deleted)
  • Never throws — catches errors and logs non-fatally
  • Skips gracefully when apiKey or externalId is missing
Orchestration Isolation
  • NO provider-specific logic in route.ts, provider-subscriptions.ts, or deploy.ts
  • All subscription logic lives on the handler (createSubscription/deleteSubscription)

Step 6: Validate Registration and Block Wiring

Trigger Registry (triggers/registry.ts)
  • All triggers are imported and registered
  • Registry keys match trigger IDs exactly
  • No orphaned entries (triggers that don't exist)
Provider Handler Registry (providers/registry.ts)
  • Handler is imported and registered (if handler exists)
  • Registry key matches the provider field on the trigger configs
  • Entries are in alphabetical order
Block Wiring (blocks/blocks/{service}.ts)
  • Block has triggers.enabled: true
  • triggers.available lists all trigger IDs
  • All trigger subBlocks are spread into subBlocks: ...getTrigger('id').subBlocks
  • No trigger IDs in triggers.available that aren't in the registry
  • No trigger subBlocks spread that aren't in triggers.available

Step 7: Validate Security

  • Webhook secrets are never logged (not even at debug level)
  • Auth verification runs before any event processing
  • No secret comparison uses === (must use safeCompare or crypto.timingSafeEqual)
  • Timestamp/replay protection is reasonable (not too tight for retries, not too loose for security)
  • Raw body is used for signature verification (not re-serialized JSON)

Step 8: Report and Fix

Report Format

Group findings by severity:

Critical (runtime errors, security issues, or data loss):

  • Wrong HMAC algorithm or header name
  • formatInput keys don't match trigger outputs
  • Missing verifyAuth when the service sends signed webhooks
  • Provider-specific logic leaking into shared orchestration files
  • Trigger IDs mismatch between trigger files, registry, and block
  • createSubscription calling wrong API endpoint
  • Auth comparison using === instead of safeCompare
  • Trigger selector credential/reference resolution occurring in the browser, or a selector missing scope authorization, credential provider binding, destination enforcement, or safe projection

Warning (convention violations or usability issues):

  • Missing extractIdempotencyId when the service provides delivery IDs
  • Timestamps in idempotency keys (breaks dedup on retries)
  • Missing challenge handling when the service requires URL verification
  • Output schema missing fields that formatInput returns (undiscoverable data)
  • Overly tight timestamp skew window that rejects legitimate retries
  • matchEvent not filtering challenge/verification events
  • Setup instructions missing important steps

Suggestion (minor improvements):

  • More specific output field descriptions
  • Additional output fields that could be exposed
  • Better error messages in createSubscription
  • Logging improvements
Fix All Issues

After reporting, fix every critical and warning issue. Apply suggestions where they don't add unnecessary complexity.

Validation Output

After fixing, confirm:

  1. bun run type-check passes
  2. Re-read all modified files to verify fixes are correct
  3. Provider handler tests pass (if they exist): bun run --cwd apps/sim test lib/webhooks/providers/<handler-basename> — handler files are kebab-case (azure-devops.ts) while trigger directories are snake_case (azure_devops), so use the handler's actual basename
  4. Any remaining unknown webhook payload schemas were explicitly reported to the user instead of guessed

Checklist Summary

  • Read all trigger files, provider handler, types, registries, and block
  • Pulled and read official webhook/API documentation
  • Validated trigger definitions: options, instructions, extra fields, outputs
  • Validated dynamic selector declarations through the shared manifest and server attachment
  • Validated primary/secondary trigger distinction (includeDropdown)
  • Validated provider handler: auth, matchEvent, formatInput, idempotency
  • Validated output alignment: every outputs key ↔ every formatInput key
  • Validated subscription lifecycle: createSubscription, deleteSubscription, no shared-file edits
  • Validated registration: trigger registry, handler registry, block wiring
  • Validated security: safe comparison, no secret logging, replay protection
  • Reported all issues grouped by severity
  • Fixed all critical and warning issues
  • bun run type-check passes after fixes

© simstudioai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/validate-trigger of simstudioai/sim.

Open the folder on GitHubat commit 546d4e7

Compare with similar skills

Validate Trigger next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Validate Trigger compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Validate Trigger this skillsimstudioai/sim30k—~3.1kAutomated safety check: PassApache-2.0
PR Review Provideryansongda/pay5.4k—~2.4kAutomated safety check: PassMIT
CLI Creatorhuangruiteng/CS-Notes4k2 repos~2.7kAutomated safety check: PassApache-2.0
Api2clialexknowshtml/api2cli455—~2.9kAutomated safety check: PassMIT
Sync APImollie/mollie-api-node297—~3.6kAutomated safety check: PassBSD-3-Clause
Dev Rulesrust-dd/tako162—~810Automated safety check: PassMIT

Similar skills

  • PR Review Provider

    yansongda/pay

    A skill your agent uses when reviewing PRs that add or modify a payment Provider in yansongda/pay - covers plugin pipeline, multi-tenant safety, signature verification, docs, and naming conventions.

    5.4k GitHub stars~2.4k tokensUpdated 9 days ago
    Backend & APIsAuto-check passed
  • CLI Creator

    huangruiteng/CS-Notes

    Build a composable CLI for Codex from API docs, an OpenAPI spec, existing curl examples, an SDK, a web app, an admin tool, or a local script.

    4k GitHub starsUsed in 2 repos~2.7k tokens
    Backend & APIsAuto-check passed
  • Api2cli

    alexknowshtml/api2cli

    Generate a working CLI from any API, then wrap it in a Claude Code skill.

    455 GitHub stars~2.9k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Sync API

    mollie/mollie-api-node

    Reconcile the SDK against the Mollie API spec — checks and optionally fixes types, JSDoc, enums, deprecations, endpoint coverage, and helper wiring.

    297 GitHub stars~3.6k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Dev Rules

    rust-dd/tako

    General coding-style rules to apply to every project. An agent skill from rust-dd/tako.

    162 GitHub stars~810 tokensUpdated 6 days ago
    Backend & APIsAuto-check passed
  • Readme Generator Pro

    beizhi23/README-Generator-Pro

    Generate, modify, and render professional README.md files and project introduction HTML pages using the bundled README Generator Pro FastAPI application.

    113 GitHub stars~472 tokensUpdated 3 mo ago
    Backend & APIsAuto-check: notes

More from simstudioai/sim

All 40 skills in this repo
  • Sim Helm

    simstudioai/sim

    Install, upgrade, and operate the Sim Helm chart on Kubernetes.

    30k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Add Column Type

    simstudioai/sim

    Add a new table column type to Sim — registry entry, icon, storage shape, coercion, and the behavioral hooks the grid and API read.

    30k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Add Enrichment

    simstudioai/sim

    Add a code-defined table enrichment (registry entry) under apps/sim/enrichments/ backed by an ordered provider cascade, ensuring every provider tool it calls has hosted-key support.

    30k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Add Hosted Key

    simstudioai/sim

    Add hosted API key support to a tool so Sim provides the key (metered and billed to the workspace) when a user has not brought their own.

    30k GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Add Managed CLI

    simstudioai/sim

    Add or upgrade a curated, immutable managed CLI for Sim Function sandboxes, including client-safe catalog metadata, a pinned server-only installation recipe, checksum and executable verification…

    30k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Add Selector

    simstudioai/sim

    Add or update a Sim dynamic selector using the shared manifest, server attachment, and selectors.execute path.

    30k GitHub stars~1.7k tokensUpdated today
    Auto-check passed

Questions about Validate Trigger

What does Validate Trigger do?

Validate an existing Sim webhook trigger against provider API docs and repository conventions. Validate Trigger is an agent skill from simstudioai/sim.

When should I use Validate Trigger?

Validate Trigger fits situations like: against provider API docs and repository conventions; tasks that involve Webhooks; tasks that involve Technical documentation.

How do I install Validate Trigger in Claude Code?

Run `npx skills add simstudioai/sim --skill validate-trigger -a claude-code`. Or copy the skill folder (.agents/skills/validate-trigger in simstudioai/sim) into .claude/skills/validate-trigger in your project. Claude Code loads it when a task matches its description.

How do I install Validate Trigger in Codex?

Run `npx skills add simstudioai/sim --skill validate-trigger -a codex`. Or copy the skill folder (.agents/skills/validate-trigger in simstudioai/sim) into .agents/skills/validate-trigger in your project. Codex loads it when a task matches its description.

Can I use Validate Trigger in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add simstudioai/sim --skill validate-trigger -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/validate-trigger, .gemini/skills/validate-trigger, .github/skills/validate-trigger and .opencode/skills/validate-trigger in your project.

What does Validate Trigger need to run?

Going by SKILL.md and its folder, Validate Trigger needs the command-line tools its instructions call (bun).

Does Validate Trigger access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Validate Trigger safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Validate Trigger use?

Validate Trigger is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Validate Trigger use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Validate Trigger?

Skills that share tags, products or a category with Validate Trigger: PR Review Provider (yansongda/pay, 5.4k stars), CLI Creator (huangruiteng/CS-Notes, 4k stars), Api2cli (alexknowshtml/api2cli, 455 stars) and Sync API (mollie/mollie-api-node, 297 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Validate Trigger?

simstudioai (a GitHub organization) maintains it in simstudioai/sim, which has 29,785 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on October 7, 2026.

Source: simstudioai/sim on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.