Content
82%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is an extremely token-dense methodology — six RCE equations, a low-severity-to-primitive mapping table, bidirectional search procedures, and a tentative-vs-confirmed validation rule — with essentially no waste. Its weaknesses are structural: a single wall-of-text code block with no section headers, and no worked example showing the search procedure applied end-to-end.
Suggestions
Break the single code block into markdown sections (e.g. '## 能力原语', '## RCE等式A-F', '## 低危→原语映射', '## 状态空间搜索', '## 突破口') so the body is navigable at a glance.
Add one compact worked example showing the backward search applied to a concrete target (facts → chosen equation → missing primitive → candidate chain → per-segment verification), which would make the abstract search procedure fully actionable.
Expand the validation guidance into an explicit checkpoint: what to record when a segment fails (note/chain tentative state), when to switch equations, and when to abandon a chain.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Every line carries a heuristic, mapping, or concrete target ('SSRF(哪怕只GET)→打内网Redis/Consul/K8s/云元数据'); there is zero padding and no explanation of concepts Claude already knows (SSRF, SSTI, TOCTOU are assumed). | 5 / 5 |
Actionability | Concrete, executable guidance throughout — specific primitive mappings, a concrete sink list ('写crontab/.bashrc/CI配置/LD_PRELOAD/authorized_keys/systemd unit都=RCE'), and a stepwise backward-search procedure — but there is no worked example walking one target from facts to a verified chain, and some directives stay abstract ('逐段验证'). | 4 / 5 |
Workflow Clarity | The state-space search is sequenced with arrows ('锁定Goal→选最接近现状的等式当模板→缺哪个原语设为子目标→…→正反向在中间相遇=完整链浮现→逐段验证') and validation is explicit ('实际执行+证据后才写 confirmed Fact', '整条链每步都验证过才成立'), but the sequence is compressed inside a single block rather than enumerated as clear steps, and error-recovery branching (what to do when a segment fails validation beyond '换等式') is thin. | 4 / 5 |
Progressive Disclosure | At ~36 lines with no bundle files, everything appropriately lives in SKILL.md, and the block has internal labeled sections (心法, RCE equations, mappings, search, breakthroughs); however the entire body is one monolithic code block with no markdown headers, which falls short of 'well-organized sections'. | 4 / 5 |
Total | 17 / 20 Passed |