Content
77%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
This is a strong, operationally dense skill body: phased workflow, hard guardrails, proof-based verdict levels, and genuine validation/stop checkpoints that are exemplary for a destructive-operation skill. The principal defects are broken bundle references — the whole templates/ directory and approval.py are cited but absent — and modest redundancy in the redaction guidance.
Suggestions
Ship the missing templates/authorization.md, templates/pentest-report.md, and templates/exploitation-queue.json files referenced in Phases 0, 3, and 5, or inline their essential contents so the workflow is self-contained.
Consolidate the credential-redaction rules stated in guardrail 6 and Phase 4 into a single authoritative location to save tokens and avoid drift.
Resolve or remove the reference to the approval.py system, which does not exist in the bundle, so destructive-payload approval has a concrete mechanism.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is dense and operational with no padding explaining concepts Claude already knows; every phase carries concrete instruction. Not 5 because there is minor redundancy (the credential-redaction rule appears in both guardrail 6 and Phase 4) and environment-specific Hermes configuration detail that could be trimmed or moved to a reference. | 4 / 5 |
Actionability | Concrete executable commands (nmap, whatweb, curl, engagement-dir setup), a verbatim authorization prompt, and specific witness payloads (' AND 1=1--, the SVG marker) cover the common cases. Not 5 because templates/authorization.md, templates/pentest-report.md, templates/exploitation-queue.json, and the approval.py system are referenced but do not exist in the bundle, leaving the queue schema and report format underspecified. | 4 / 5 |
Workflow Clarity | Phases 0-5 are clearly sequenced with explicit validation checkpoints (authorization gate, per-request scope check, pre-send checks, bypass-exhaustion before false-positive classification) and error-recovery feedback loops plus a 'When to Stop' section. The destructive-operation cap does not apply because validation and approval gates are pervasive. | 5 / 5 |
Progressive Disclosure | The body is well-structured with one-level-deep, clearly signaled references and a Further Reading index, but scored against the actual bundle: 3 of the 8 referenced paths (the entire templates/ set) plus approval.py are missing, so a third of the navigation targets are dead. This drags it below the 'mostly clear' anchor 4. | 3 / 5 |
Total | 16 / 20 Passed |