Content
50%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A highly actionable, well-sectioned Django security reference with strong GOOD/BAD code contrasts, but it is a monolithic ~590-line single file that largely restates Django knowledge Claude already has, with notable duplication across sections and no external reference files or sequenced review workflow. It would benefit substantially from splitting into reference files and trimming boilerplate.
Suggestions
Split into reference files (e.g., references/settings.md, references/api-security.md, references/file-uploads.md) and keep SKILL.md as a lean overview with a pointer to each, rather than inlining ~590 lines.
Remove the duplicated material — security headers appear in three sections (核心安全设置, HTTP 头部, 安全头部) and SECRET_KEY handling is shown twice — and delete boilerplate Django settings Claude already knows, keeping only project-specific decisions and the GOOD/BAD contrasts.
For the stated security-review use case, add a short sequenced workflow (e.g., 1. check DEBUG/ALLOWED_HOSTS/SECRET_KEY, 2. review auth/permission code, 3. audit raw SQL and mark_safe usage, 4. verify headers/CSP via the checklist) so the topical content becomes an actionable review process.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | At ~590 lines the body re-teaches standard Django security knowledge Claude already knows (SECURE_SSL_REDIRECT/HSTS/cookie flags, ORM parameter escaping, DRF permission classes) and duplicates content across sections — security headers appear in "核心安全设置" and again in "HTTP 头部" and "安全头部", SECRET_KEY handling is covered twice with two different code approaches, CSRF cookie settings repeat. This matches the anchor 'noticeably verbose; several unnecessary explanations or padded sections' rather than anchor 3's 'mostly efficient with some trimming needed'. | 2 / 5 |
Actionability | The content is dominated by concrete, near copy-paste-ready code — production settings, custom user model, DRF permissions and throttles, validators, middleware, logging config — plus good GOOD/BAD contrasts for SQL injection (parameterized raw() vs f-string) and XSS (mark_safe vs format_html). It falls short of anchor 5 because several snippets have undefined names (ImproperlyConfigured never imported, Response used without import in protected_view, User referenced in Post and permissions snippets without definition), so they are not fully executable as written. | 4 / 5 |
Workflow Clarity | The body is organized topically rather than as a workflow: there is a useful "何时启用" trigger list and a final security checklist, but no sequenced process (e.g., audit settings → fix → verify) and no validation checkpoints despite the skill explicitly targeting '审查 Django 应用程序的安全问题' (reviewing security issues), where a review-then-verify flow matters. This matches anchor 3: structure present, checkpoints missing or implicit. | 3 / 5 |
Progressive Disclosure | The single SKILL.md is well-sectioned with clear ## headers (no wall-of-text problem), but it is ~590 lines of reference material inlined with zero bundle files — no references/, scripts/, or assets/ exist. Per the guideline, the under-50-lines exception does not apply, and content that clearly belongs in separate files (full settings catalogs, DRF/API security, CSP middleware details, logging config) is inlined. This matches anchor 3: 'some structure but could be better organized; content that should be separate is inline', stopping short of anchor 2 because section structure and navigation within the file are genuinely good. | 3 / 5 |
Total | 12 / 20 Passed |