Content
75%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A well-engineered reference skill: prescriptive, information-dense rules with specific thresholds and commands, clearly sequenced mini-workflows with validation checkpoints, and exemplary one-level-deep linking into a real reference file. The main deductions are trimmable explanatory material (STRIDE and rationalizations tables), some policy-level directives lacking executable detail, and a dangling `../../references/security-checklist.md` reference that does not exist in the bundle.
Suggestions
Fix or inline the three references to `../../references/security-checklist.md` — the path leaves the skill bundle and does not resolve; either ship the checklist as `references/security-checklist.md` or fold its unique content (manager matrix, install-script gate, worked destructive-path code) into hardening-patterns.md.
Trim concept-review material Claude already knows — the STRIDE table can shrink to one line per threat, and the Common Rationalizations table can drop rows whose rebuttals are obvious (e.g., "It's just a prototype", "No one would try to exploit this").
Convert the remaining policy-level directives into concrete steps, e.g. specify what "pin the resolved IP" and "inspect the pending script source" look like in practice (commands or a short worked example), since the dependency and SSRF sections otherwise carry exact, actionable detail.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is dense and prescriptive — specific values like "bcrypt (≥12 rounds)", "about 10 attempts per 15 minutes", "`169.254.169.254`", and non-obvious caveats like the DNS-rebinding TOCTOU gap and "in-memory counters silently become `max × instances`" earn their tokens. It sits at anchor 4 rather than 5 because some material assumes less competence than needed: the STRIDE table, the "Common Rationalizations" table (10 rows of rebuttals), and repeated trust-boundary explanations in two sections could be trimmed without losing guidance. | 4 / 5 |
Actionability | Guidance is largely concrete and directive — named algorithms and parameters ("`sameSite: 'lax'` or `'strict'`", "`default-src 'self'`"), exact commands ("`npm audit signatures`"), and precise conditions ("resolve **all** DNS records and reject any private or reserved address"). Per the scoring note, absent code is not penalized in an instruction-only skill, but some directives remain policy-level without executable detail ("a documented fail-closed policy", "pin the resolved IP", "inspect the pending script source"), matching anchor 4's "concrete code or commands with minor gaps" rather than anchor 5's fully copy-paste-ready coverage. | 4 / 5 |
Workflow Clarity | Multi-step processes are clearly sequenced with checkpoints: the four-step threat-model process with a stop condition ("If you can't name the trust boundaries... you're not ready"), the four-step dependency workflow with validation ("stop on disagreement", "verify with a clean frozen/immutable install"), the three-condition pre-check for destructive operations, and a full Verification checklist. It falls short of anchor 5 because error-recovery feedback loops are thin in the body — most stop-conditions ("log the rejected target and stop") halt rather than loop back, and full recovery guidance is deferred to references. | 4 / 5 |
Progressive Disclosure | Structure is genuinely good: the body is an overview of rules, each control section links one level deep to real, verified anchors in references/hardening-patterns.md, and navigation is explicitly paced ("Open the section you need when you reach that code, not before"). It misses anchor 5 because the body references `../../references/security-checklist.md` three times — including as the centerpiece of the Review Checklist section — and that path escapes the bundle and does not resolve, leaving a dangling, unverifiable reference within otherwise clean navigation. | 4 / 5 |
Total | 16 / 20 Passed |