Review the reliability and security of webhook delivery (outbound) and webhook handling (inbound) — signature verification, replay protection, retries with backoff, idempotent receipt, ordering, timeouts, and failure visibility — by reading the sender, receiver, and their config in the actual codebase. Use when a webhook producer or consumer is added or changed, when webhooks are missed, duplicated, processed out of order, or fail signature checks, or when integrating a third-party webhook (Stripe/GitHub/Twilio/etc.). Produces a webhook reliability findings report grounded in the code. For a live delivery incident in production, use service-debugging.