Content
88%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
An exceptionally actionable, workflow-driven skill: concrete probes, explicit diagnostic ordering, mandatory verification gates, and pivot discipline that anticipate known agent failure modes (false-positive 200s, iterating dead vectors). The two moderate weaknesses are repetition of payload classes across sections and a monolithic single-file structure where the nginx-alias and Protected-LFI deep-dives could be split into reference files.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Nearly every token is an executable command, payload, or decision rule — there is no padding and no explanation of concepts Claude already knows (the "Why it works" nginx-alias derivation is genuinely specialized). However, payload classes recur across sections: "....//....//....//etc/passwd" appears in Detection, Bypass Techniques, the Decision Tree, and the Protected-LFI section, and log poisoning is documented three times. This fits "efficient; minor instances ... that could be trimmed" (4) rather than level 5's "every token earns its place". | 4 / 5 |
Actionability | Every technique is given as copy-paste-ready curl/bash with concrete payloads (plain, URL-encoded, double-encoded, null-byte, Windows backslash, "....//" stripping bypass, php://filter chains, log/session poisoning) plus grep-based PASS/FAIL checks against saved responses. Placeholders like <TARGET> and <PARAM> are simple substitutions, so the guidance is fully executable and covers the common cases — the level 5 anchor. | 5 / 5 |
Workflow Clarity | The body provides an explicit Decision Tree, a mandatory Probe A/A2/B/C diagnostic ordering for protection classes, the STEP W1 wrapper-availability gate with an explicit failure branch ("jump to W5"), and a MANDATORY Response Body Verification step with baseline-size comparison, file-signature greps, and a known-content control file (etc/hostname). This is a clear sequence with explicit validation steps, error-recovery feedback loops, and pivoting rules — the level 5 anchor; it exceeds level 4, whose checkpoints would only be "mostly" present. | 5 / 5 |
Progressive Disclosure | This is a single-file skill (no references/, scripts/, or assets/ exist) with well-signaled sections and an internal decision tree for navigation. Structure is good, but at ~320 lines the deep-dive material (the nginx alias off-by-slash analysis and the ~90-line Protected LFI Escalation Rule) would arguably live better in one-level-deep reference files, leaving SKILL.md as a leaner overview. That fits "good structure; most content appropriately placed; minor organization gaps" (4) rather than level 5's cleanly split content. | 4 / 5 |
Total | 18 / 20 Passed |