Content
62%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is maximally token-efficient and dense with domain-specific facts, but it reads as a flat vulnerability checklist rather than an operational skill: no executable commands and no sequenced audit workflow with validation steps. Converting the implicit source→automated→manual flow into explicit steps with runnable tool invocations would substantially raise actionability and workflow clarity.
Suggestions
Add runnable commands for the automated phase, e.g. a concrete slither invocation ('slither . --detect reentrancy-eth reentrancy-no-eth') and the Etherscan getsourcecode API URL template, so the guidance is copy-paste executable.
Restructure the implicit phases into an explicit numbered workflow (1. fetch & verify source matches on-chain bytecode, 2. run slither/mythril, 3. manual checks by category, 4. confirm findings against PoC) with a validation checkpoint before reporting a vulnerability as exploitable.
Replace the single monolithic code block with short labeled sections (Source retrieval / Automated analysis / Manual checks / DeFi & bridges) so the card is scannable and each category can be extended without re-formatting.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is an extremely lean reference card — no padding, no explanations of concepts Claude already knows; every token carries a specific fact (tool names, C-E-I ordering, port 8545, eth_sendTransaction). Matches anchor 5 ('every token earns its place'). | 5 / 5 |
Actionability | Concrete specifics are present ('slither/mythril/manticore', '.call{value}先转账后改状态', '<0.8无SafeMath', 'block.timestamp可控', '暴露8545直接eth_sendTransaction') but there are no executable commands (e.g., an actual slither CLI invocation or Etherscan API call). Anchor 3 ('some concrete guidance but incomplete; missing key details') fits better than 2, since these are far more than high-level hints. | 3 / 5 |
Workflow Clarity | Only a rough implicit three-phase grouping (源码 obtain source → 审计 automated tools → 手工 manual review) with no explicit sequencing and no validation checkpoints for an audit workflow — anchor 2 ('rough sequence present but many gaps; validation absent'), above anchor 1 since a coarse sequence is discernible. | 2 / 5 |
Progressive Disclosure | No bundle files exist and the body is short, so nothing needs splitting; however the entire skill is a single monolithic code block under one heading with internal labels rather than clearly organized sections — anchor 4 ('good structure; minor organization gaps') rather than 5's well-organized sections. | 4 / 5 |
Total | 14 / 20 Passed |