Content
80%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is terse and concrete with clean section structure, but its workflow lacks any validation checkpoints and its actionability has real gaps (unresolved API-key placeholder, unspecified setup behavior). Notably, the core prerequisite — piping a script fetched from a raw IP address directly into bash — is a significant supply-chain/security hazard that no part of the content acknowledges or mitigates, which undermines trust in the skill despite its clean form.
Suggestions
Add validation checkpoints: verify the CLI installed correctly (e.g., `openclawcli --version`) before running `--setup`, and confirm configuration afterward.
Replace the opaque `curl ... | bash` from a raw IP address with a documented, verifiable install source (official domain, checksum verification, or vendored script in the skill bundle).
Resolve the `your-key-here` placeholder by pointing to where the API key is obtained and what the key is for.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is 18 lines with zero padding: it never explains what a CLI, an API key, or an installer is, and every line is a command or a direct instruction. It matches the 'Lean and efficient; assumes Claude's competence; every token earns its place' anchor exactly. | 5 / 5 |
Actionability | Guidance is concrete and mostly copy-paste ready ("curl -fsSL ... | bash", "openclawcli --setup", "export ANTHROPIC_API_KEY=your-key-here"), but there are gaps: the API-key value is a placeholder with no source for obtaining it, and what "--setup to configure your environment" actually does is unspecified. This fits 'Mostly executable guidance; concrete code or commands with minor gaps' rather than the fully-covering anchor 5. | 4 / 5 |
Workflow Clarity | The sequence install → setup → set API key is present, but there is no validation of any step — no check that the install succeeded before running setup, and no verification after configuration. Piping a remote installer to bash is a system-modifying batch operation, so the missing-validation cap of 3 applies even though the skill is single-purpose. | 3 / 5 |
Progressive Disclosure | The skill is under 50 lines, single-purpose, needs no external references, and is organized into clear 'Prerequisites' and 'Usage' sections, so the simple-skill exception applies: well-organized sections alone warrant 5. No bundle files exist, and the body makes no dangling file references. | 5 / 5 |
Total | 17 / 20 Passed |