Content
57%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The content is a dense, token-efficient method map for 0day discovery that correctly names the right tools and includes a verification checklist, but it stops short of being actionable: no executable commands, example queries, or harness code. Formatting everything into one code block also hurts navigability despite the small size.
Suggestions
Convert the code block into headed markdown sections (one per approach, plus 'Hunter mindset' and 'Verification') so the map is scannable.
Add one concrete executable artifact per major path — e.g., a minimal CodeQL taint-tracking query for the taint approach, an AFL++/libFuzzer harness skeleton, and a variant-analysis grep/semgrep command line.
Add a selection heuristic (which path to try first given source access, patch availability, or protocol access) and a failure-handling loop for the verification step (e.g., what to do when a crash is not reproducible).
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is very dense and token-efficient: it assumes competence (names AFL++, libFuzzer, boofuzz, radamsa, restler, CodeQL, Semgrep, Joern, bindiff, diaphora without explaining them) and wastes little on background. Minor trimming is possible (e.g., the parenthetical tool annotations), and the choice to pack everything into one code block makes it harder to scan than plain markdown would be. | 4 / 5 |
Actionability | Concrete method outlines are present ('拿一个CVE补丁→提炼漏洞模式→全库grep同模式其它位置') and specific tools are named per approach, but there are no executable commands, no example CodeQL/Semgrep queries, no harness skeleton, and no crash-triage procedure — the guidance reads as a high-level method map rather than steps Claude can directly execute. | 3 / 5 |
Workflow Clarity | The five approaches are enumerated and a verification section exists ('0day验证: 可复现(最小PoC)+根因清楚+影响可证+排除误报'), which serves as a validation checkpoint. However, there is no guidance on selecting among the five paths, no ordering across them, and no feedback loop (what to do when verification fails or a crash is not reproducible), so checkpoints remain implicit. | 3 / 5 |
Progressive Disclosure | At ~30 lines with no bundle files (no references/, scripts/, or assets/ exist), the skill could qualify for a 5 with well-organized sections, but the entire body is a single monolithic code block under one heading — the five methods, hunter-mindset checklist, and verification criteria are not separated into scannable sections, so structure is present but poorly organized. | 3 / 5 |
Total | 13 / 20 Passed |