Content
75%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is efficient and grounded: it separates upstream defaults (delegated to a real, well-scoped reference file) from repository-made decisions, and states those decisions as explicit, executable rules. Weaknesses are modest: an undefined-helper code snippet, trimmable framing prose, and inline version-specific details that belong in the reference.
Suggestions
Define or inline the helpers used by buildTrustedOrigins (isLocalDeployment, productionOrigins, devOrigins) so the snippet is copy-paste ready, or label it explicitly as illustrative.
Move the version-specific linking-gate details (the 1.5.6 pseudo-block and the pre-requireLocalEmailVerified history) into references/configuration.md under a clearly signaled section, keeping only the durable rules in SKILL.md.
Trim the rhetorical framing sentence about 'account-takeover or open-redirect surface rather than a misconfiguration' to one clause, keeping the motivating why without the padding.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is lean and assumes competence, but the framing sentence "getting either wrong is an account-takeover or open-redirect surface rather than a misconfiguration" is trimmable rhetoric, and bare version numbers ("better-auth 1.5.6") are time-sensitive details not placed in an old-patterns section. Fits anchor 4: efficient with minor over-explanation. | 4 / 5 |
Actionability | Concrete decision rules ("never add github to trustedProviders", "Never list email-password in trustedProviders") and real TS/code blocks are present, but buildTrustedOrigins calls undefined helpers (isLocalDeployment, productionOrigins, devOrigins) and the linking gate is a txt pseudo-block, so it is mostly rather than fully executable. Anchor 4, not 3, because the surrounding guidance is directly actionable. | 4 / 5 |
Workflow Clarity | A clear grounding sequence is given ("ask DeepWiki a narrow question ... then verify decisive details against local installed types, source, or official docs" before "Read references/configuration.md"), but the audit workflow itself has no validation checkpoints. Anchor 4: clear sequence with most checkpoints, minor validation gaps. | 4 / 5 |
Progressive Disclosure | "Read [references/configuration.md](references/configuration.md) when configuring or auditing an option" is a well-signaled, one-level-deep reference whose stated scope matches the actual file, but version-specific gate details (the 1.5.6 linking logic) are inlined in SKILL.md rather than delegated to the reference. Anchor 4: good structure with minor organization gaps. | 4 / 5 |
Total | 16 / 20 Passed |