Content
61%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is an extremely token-efficient, highly actionable reversing playbook with concrete commands and anticipated pitfalls, though its multi-step flows lack explicit validation checkpoints. Its biggest defect is structural: it references four bundle files that are absent from the skill, and inlines dense per-platform detail that belongs in those files.
Suggestions
Create the referenced bundle files (references/uniapp-apk-reverse-engineering.md, references/uniapp-apk-reversing.md, scripts/js_rc4_deobfuscate.js, scripts/chengzi_decrypt.py) or remove the broken reference line — currently every cited path is a dead link.
Split the deep per-platform detail (UniApp config-decryption offset tables, RC4 deobfuscation internals, ChengZi SDK decryption) into the per-topic references/*.md files, keeping SKILL.md as a short index with one 🚨 line per platform.
Add explicit validation checkpoints to the multi-step flows (e.g., verify the decoded JS parses with node before batch-decoding, confirm the extracted domain responds before treating it as an API host) with fix-and-retry guidance.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Dense telegraphic notes with essentially zero padding and no explanation of concepts Claude already knows; the .so string-deobfuscation pattern is repeated in both the UniApp section and the generic section, a minor duplication that keeps it below anchor 5. | 4 / 5 |
Actionability | Concrete copy-paste commands throughout ("apktool d / jadx", "strings -n8 libapp.so|grep 'https\?://'", "objection android sslpinning disable", "binwalk -Me"); the JS RC4 deobfuscation flow is described as an algorithm in prose rather than executable code, leaving minor gaps versus anchor 5. | 4 / 5 |
Workflow Clarity | Sequences are conveyed via arrow chains (checksec → primitive → info leak → ROP → heap → arbitrary write) and 🚨 trap notes anticipate failure modes, but there are no explicit validation checkpoints or fix-and-retry feedback loops, matching anchor 3. | 3 / 5 |
Progressive Disclosure | The body cites four bundle files ("references/uniapp-apk-reverse-engineering.md", "scripts/js_rc4_deobfuscate.js", "scripts/chengzi_decrypt.py") that do not exist in the bundle, and deep per-platform detail (zlib header offset tables, RC4 decoding internals) is inlined in one monolithic block instead of being split into those references — anchor 2, since the references are broken rather than merely unclear. | 2 / 5 |
Total | 13 / 20 Passed |