Content
82%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A strong, dense audit playbook: threat model, per-channel checklists, executable greps, and a rigorous PoC-required reporting format, with no padding and no hand-holding. Its main weaknesses are two repo-specific leftovers that assume context absent from the skill, the lack of an explicit iterate-on-failure loop, and all detail inlined in one file rather than split across references.
Suggestions
Remove or generalize the repo-specific references ("this repo's own server", "this repo ships a redact.py") — they point to code and files that are not part of the skill bundle and will confuse a generic deployment.
Add a short iteration loop for findings, e.g. 'if the PoC call fails, re-check whether the sink is reachable; only report after a confirmed call' — this would close the workflow_clarity gap between checkpoints and a recovery loop.
Consider moving the per-threat deep-dives (§2–§7) or the source-audit grep recipes (§8) into a references/ file, keeping SKILL.md as the threat-model overview plus quick-kill checklist.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is lean, checklist-driven, and assumes Claude's competence (no re-explanation of SSRF, path traversal, or command injection). However, two lines are repo-context leftovers that don't earn their place in a standalone skill: "Good sign (this repo's own server): active tools require `approve=true`..." and "this repo ships a `redact.py` — check it actually covers the tokens in scope", which reference context not present in the bundle. | 4 / 5 |
Actionability | Fully executable guidance: copy-paste-ready grep recipes for both Python and Node ("grep -rnE \"os\\.system|subprocess.*shell=True|eval\\(|exec\\(|open\\(.*\\.\\.\" ."), a concrete tool-shape-to-bug mapping table, and a fill-in report template with exact fields including a mandatory "PoC: <exact tool call + input that proves it>". This is an instruction-heavy skill and its guidance is specific throughout. | 5 / 5 |
Workflow Clarity | A clear sequence exists (§0 quick-kill checklist → threat model → per-channel hunts → §8 source greps → §9 report format) with real validation checkpoints ("Confirm reachability before you write it up", "Kill anything you can't prove with a concrete call"). It falls short of the anchor-5 pattern because there is no explicit error-recovery or iteration loop between checkpoints. | 4 / 5 |
Progressive Disclosure | Ten well-organized, clearly headed sections in a single ~160-line file with no external references. Structure is good, but the skill exceeds the under-50-line simple-skill exception and inlines per-threat-class deep-dives and grep recipes that could live in reference files; additionally, the "this repo's own server" / "redact.py" mentions point to bundle files that do not exist, which is a minor organization/navigation gap. | 4 / 5 |
Total | 17 / 20 Passed |