Content
72%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A well-structured audit-checklist skill with excellent progressive disclosure (a verified one-level reference) and largely actionable detection signals. The main gaps are workflow clarity — the audit sequence is only partially ordered and lacks an explicit verify/report checkpoint, with an empty P0 header hinting at dropped content — and minor token waste from the dangling 'Canonical response anchors' section.
Suggestions
Add an explicit step-by-step audit sequence covering all ten LLM risks (not just LLM01 and LLM06) ending with a validation/reporting checkpoint, e.g. '4. Re-verify every 🔴 item against references/owasp-llm.md before reporting; 5. Summarize findings with severity and the capped score.'
Fix or remove the empty '## **Priority: P0 (CRITICAL)**' header and the 'Canonical response anchors' section that ends in a single dangling '- sanitize' bullet — either complete these sections or delete them to remove ambiguity and wasted tokens.
Tighten the Implementation Guidelines bullets by attaching a concrete example to each (e.g. 'pin source revision and hashes' → 'record sha256 of each package in a lockfile and verify on install') so the guidance is copy-paste actionable without loading the reference.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is lean — a compact 10-row table of detection signals and terse bullets with no explanations of concepts Claude already knows — matching anchor 4. It misses anchor 5 because of small wastes: an empty '## **Priority: P0 (CRITICAL)**' header with no content beneath it, a 'Canonical response anchors' section ending in a single dangling item ('- sanitize'), and awkward phrasing like '— not skip any item'. | 4 / 5 |
Actionability | Guidance is mostly executable for an audit workflow: ordered checks ('Check LLM01 first', 'Check LLM06 next'), a marking scheme ('✅ not affected | ⚠️ needs review | 🔴 confirmed finding'), a scoring rule ('P0 finding caps Security score at 40/100'), and concrete per-risk signals like 'No `max_tokens` on LLM call. No rate limit on invocations.' This matches anchor 4; it is not 5 because fix guidance lives entirely in the reference file and a couple of guidelines (e.g. 'pin source revision and hashes') lack concrete examples inline. | 4 / 5 |
Workflow Clarity | A partial sequence exists (LLM01 first, LLM06 next, then 'mark each item'), but the remaining eight risks are unsequenced and there is no explicit validation or reporting checkpoint — the marking scheme is implied rather than a stated verify/report step. This matches anchor 3 ('steps listed but validation gaps; checkpoints missing or implicit'), and the empty P0 priority header suggests missing workflow content that would be needed for anchor 4. | 3 / 5 |
Progressive Disclosure | SKILL.md is a genuine overview: a summary table of the ten risks with key signals, while full detection signals are split into one real, one-level-deep reference (references/owasp-llm.md, verified to exist, 115 lines) that is clearly signaled twice with load-when guidance ('load when auditing any LLM client code'). This matches anchor 5 — clear overview, well-signaled one-level-deep references, easy navigation — and is above anchor 4 because nothing that belongs in the reference is inlined and no reference is buried. | 5 / 5 |
Total | 16 / 20 Passed |