Content
82%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A highly actionable, well-structured scan procedure: executable grep targets, concrete fixes, an exact output template, and clear sequencing with a caller-facing PASS/FAIL contract. The main improvement opportunities are consolidating version/chatty asides, adding an explicit HIGH-finding verification checkpoint, and moving the per-category pattern tables into reference files.
Suggestions
Add an explicit verification step between Step 2 and Step 4 (e.g., 'Re-confirm each HIGH finding against the source line before declaring FAIL') to sequence the anti-hallucination intent of Rule 1 into the workflow.
Trim conversational asides ("Why this matters", "which is great — but there are escape hatches") and consolidate the scattered "New in 2025" version notes into a single note near the top.
Consider moving the ten per-category check tables into a references/ file (e.g., references/owasp-checks.md) so SKILL.md stays a lean overview of procedure and report format.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Dense grep-pattern tables, severity guides, and a copy-paste report template with almost no filler; it assumes Claude's competence throughout. Not 5 because of a few trimmable asides ("Why this matters: the #1 vulnerability", "React's JSX auto-escapes by default, which is great") and scattered "New in 2025" version notes outside any consolidated section. | 4 / 5 |
Actionability | Concrete grep targets per check ("jwt.decode (should be jwt.verify)", "cacheLocation: 'localStorage'", a literal ``SELECT.*\$\{`` pattern), exact fix snippets ("@Microsoft.KeyVault(SecretUri=...)", tenant-specific authority URL), and a fully specified report format. This is copy-paste-ready guidance covering the common cases of the target stack. | 5 / 5 |
Workflow Clarity | Steps 1-5 are clearly sequenced with a per-category checklist, a PASS/FAIL exit contract for callers, an ignore-comment escape hatch, and skip rules with reporting requirements. Not 5 because there is no explicit checkpoint to re-verify HIGH findings before declaring FAIL — Rule 1 ("Don't hallucinate findings") implies it but does not sequence it into the workflow. | 4 / 5 |
Progressive Disclosure | The body is cleanly sectioned (Purpose, When to Use, Composability, per-category checks, Azure config, report format, Rules) with no buried or nested references and no bundle files to navigate. Not 5 because ~200 lines of per-category pattern tables sit fully inline in the always-loaded SKILL.md where a one-level references split could lighten it. | 4 / 5 |
Total | 17 / 20 Passed |