Content
85%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A well-engineered router skill: tight operational rules, a gated three-leg hunt procedure with explicit validation and retry semantics, and clean one-level-deep disclosure into an existing, well-organized reference bundle. The only weaknesses are mildly wordy rule explanations and the absence of any complete inline DQL query.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is dense and operative — no filler, no explaining concepts Claude already knows, and every rule carries Dynatrace-specific facts Claude cannot infer (e.g. "there is no `threat.observables.hosts` field", retry ladder "15m then 5m"). It falls short of the lean "every token earns its place" anchor only in wordy passages such as the summarize-first rule ("Summarize-first ≠ truncation: the rollup preserves every affected entity...") and the rule-10 carve-out justification, which could be trimmed without losing guidance. | 4 / 5 |
Actionability | Concrete, executable fragments appear throughout — `matchesPhrase(content, "<ioc>")`, `iAny(contains(content, allObservables[]))`, `in(ip(actor.ips), array(...))`, `lower(url.*)`, `from:now()-30m`, chunk sizes ("default 25 IoCs; 10 for long URLs/emails/hashes") — plus exact per-leg file loads. It is not 5 because the body deliberately routes full copy-paste DQL queries into the reference files rather than including any complete executable query inline, leaving minor gaps if a reference were unavailable. | 4 / 5 |
Workflow Clarity | The "Mandatory Hunt Procedure" gives an explicit ordered three-leg sequence with a hard gate ("Do not proceed to `exposure-scoring.md` until all three legs are done"), per-leg outcomes (zero rows = valid no-match; `FETCH_EXEC_TIME_LIMIT` = INCONCLUSIVE), an automatic retry ladder (30m → 15m → 5m) with approval gating for widening, and a completeness rule ("A no-match conclusion is valid only if every chunk completes cleanly"). This matches the anchor with explicit validation steps, feedback loops, and error-recovery paths. | 5 / 5 |
Progressive Disclosure | The body is a router/overview pointing to seven one-level-deep reference files, all of which exist in `references/` (verified: hunt-logs.md, hunt-spans.md, hunt-security-events.md, ioc-intake.md, exposure-scoring.md, timeframe-gating.md, secondary-observable-extraction.md). Navigation is well-signaled via the IoC-type routing table, the "When to Use This Skill" intent→reference table, and inline references; detailed DQL is correctly deferred to those files. No nesting or dangling paths. | 5 / 5 |
Total | 18 / 20 Passed |