Together Webhooks EventsSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| cursor | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: together-webhooks-events description: >- Convert Together AI batch, fine-tuning, upload, and dedicated-deployment job states into idempotent internal events using bounded polling and an optional owned callback. Use when integrating asynchronous Together work. Trigger with "Together job events", "Together callback", or "poll Together status". argument-hint: "[repository-path] [batch|fine-tune|upload|deployment]" allowed-tools: Read, Glob, Grep, WebFetch, Write, Edit version: 1.9.0 author: Jeremy Longshore <[email protected]> license: MIT tags: - saas - together-ai - asynchronous-jobs model: inherit effort: high compatibility: Designed for Claude Code; polling requires authorized Together AI project access --- # Together AI Job Events ## Overview Together documents asynchronous retrieval and polling for batch, fine-tune, upload, and deployment state. This skill emits internal events from that source of truth instead of inventing a provider-signed webhook. ## Prerequisites - The job type, ID, project, terminal states, and retrieval method - A durable cursor/state store and idempotency key policy - Poll interval, deadline, retry budget, and event retention policy - An owned callback endpoint only if downstream push delivery is required ## Tool Discipline Use `Read`, `Glob`, and `Grep` to inspect job persistence, pollers, queues, and callback handlers. Use `WebFetch` to confirm current job states and retrieval methods. Use `Write` or `Edit` only after the event contract and storage boundary are approved. ## Current Contract - Do not expect a universal Together webhook signature header; no general signed webhook surface is documented for these job APIs. - Persist the provider job ID before polling and derive internal idempotency from job ID plus observed state/version. - Treat terminal job status and per-item output/error artifacts as separate facts. - Deliver downstream callbacks from infrastructure you own and authenticate them with your own signing scheme. ## Authentication Poll Together with the project-scoped `TOGETHER_API_KEY` Bearer credential. For an owned callback, use a separate secret, timestamped signature, replay window, and rotation plan; never present that signature as Together-generated. ## Instructions 1. Map provider job states to a small versioned internal event schema. 2. Persist job ID, last observed state, next poll time, attempt count, and deadline. 3. Retrieve with bounded exponential backoff and jitter; stop at terminal state or deadline. 4. Emit only on meaningful transitions and deduplicate by job/state key. 5. On completion, fetch output and error artifacts before declaring record-level success. 6. If needed, sign and deliver an internal callback with replay protection and a dead-letter path. ## Approval Boundaries Do not expose the Together key to callback consumers, invent provider signatures, or delete remote/local job artifacts before reconciliation and retention approval. ## Output Return the provider job reference, state mapping, poll schedule, transition ledger, reconciliation status, callback delivery evidence, and deadline/dead-letter disposition. ## Error Handling | Condition | Response | |---|---| | Retrieval is transiently unavailable | Retry with jitter inside the overall deadline. | | Job ID is missing | Stop; do not create a replacement job automatically. | | Completion has an error file | Emit completed-with-errors and reconcile records. | | Callback repeatedly fails | Preserve the event in a dead-letter queue for replay. | ## Examples The example below shows the minimum redacted evidence expected from a successful invocation of this operator workflow. ```text job=batch-redacted; transition=IN_PROGRESS->COMPLETED; records=reconciled; callback=owned-signed ``` ## Resources - [Skill-specific official documentation](references/official-docs.md) - [Batch tutorial](https://docs.together.ai/docs/inference/batch/tutorial) - [Fine-tuning lifecycle](https://docs.together.ai/reference/cli/finetune) - [Dedicated Model Inference](https://docs.together.ai/docs/dedicated-endpoints/overview)
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__together-webhooks-events.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Together Webhooks Events skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Together Webhooks Events safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Together Webhooks Events access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Together Webhooks Events work with?
Its documentation mentions claude-code and cursor. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.