Content
85%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is an exceptionally lean, fully executable search playbook with a well-sequenced mandatory workflow and a genuine error-recovery feedback loop. Its main weakness is organization: everything sits in a single undifferentiated code block with no section structure, and a couple of commands mix shell syntax into browser navigation.
Suggestions
Break the single code block into markdown sections (e.g., '## Mandatory search sequence', '## When a search is blocked', '## Escalation') so the fallback ladder and main sequence are navigable at a glance.
Move the fofa lookup to a terminal command that computes the base64 query (e.g., a curl/terminal step instead of embedding $(...) substitution in a browser_navigate URL), and note that GitHub code-search API calls require an auth token.
Consider splitting the blocked-fallback ladder into a reference file (e.g., references/blocked-search.md) and signaling it clearly, keeping SKILL.md as a tight overview of the 7-step sequence.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Every line is a command, URL, or instruction; there is no explanation of concepts Claude already knows and no padding, with lean {C}/{V} templating throughout. | 5 / 5 |
Actionability | Commands are concrete and mostly copy-paste ready (searchsploit, curl|python3 one-liners, browser URLs), but minor gaps exist: the fofa URL embeds a $(echo -n ... | base64) shell substitution inside a browser_navigate, and the GitHub code-search API call requires authentication it doesn't mention. | 4 / 5 |
Workflow Clarity | A clear mandatory sequence (steps 1-7) with per-step tool assignments, an explicit error-recovery ladder triggered by concrete failure signals ("碰到403/验证码/空结果/超时→按序执行不放弃"), and a defined terminal handoff ("全部受阻仍无结果→...→转 zero-day-discovery") plus a results-verification discipline stated up front. | 5 / 5 |
Progressive Disclosure | No bundle files exist, and the entire body is one monolithic code block with no markdown section headers; the blocked-fallback ladder is buried inline and cross-skill references (proxy-tool-bootstrap, zero-day-discovery) are not clearly signaled, though the internal numbering keeps it coherent. | 3 / 5 |
Total | 17 / 20 Passed |