Content
63%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A dense, largely executable Django security reference with strong code examples and a useful closing checklist, organized into clear topical sections. Its weaknesses are monolithic structure (no reference files despite ~590 lines), duplicated blocks that waste tokens, and a few non-executable or internally contradictory snippets (CSRF HttpOnly vs. the JS cookie reader). Splitting topics into references/ and adding a deploy-check verification step would raise both structure scores.
Suggestions
Split the body into references/ files (e.g., references/api-security.md, references/file-uploads.md, references/deployment.md) and keep SKILL.md as a concise overview with well-signaled links plus the quick checklist.
Remove duplicated blocks: define the custom User model once, merge the two security-header/CSP middleware sections, and consolidate the two REST_FRAMEWORK dicts.
Add an explicit validation step such as `python manage.py check --deploy`, and fix the CSRF_COOKIE_HTTPONLY = True setting that contradicts the JavaScript getCookie('csrftoken') example.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Prose is minimal and the body is mostly code, but there is noticeable duplication that could be trimmed: the custom User model is defined twice (認証 and RBAC sections), security headers and CSP middleware appear in two sections, and there are two separate REST_FRAMEWORK dicts plus repeated ALLOWED_HOSTS/SECRET_KEY settings. This fits 'mostly efficient but includes some unnecessary content or could be tightened' rather than the fully lean 4-5 band. | 3 / 5 |
Actionability | Most guidance is concrete, executable settings and code (production settings, password validators, DRF permissions, file validators, GOOD/BAD SQL examples), matching 'mostly executable with minor gaps'. It is not 5 because several blocks are not copy-paste ready: the CSP middleware references undefined CSP_* constants, ImproperlyConfigured is raised without being imported, and CSRF_COOKIE_HTTPONLY = True contradicts the JavaScript getCookie('csrftoken') example that depends on reading that cookie. | 4 / 5 |
Workflow Clarity | As a reference-style skill it is well organized: an explicit 'いつ有効化するか' activation list, clearly sequenced topic sections, and a final quick-check checklist that acts as a verification artifact, matching 'clear sequence with most checkpoints present; minor validation gaps'. It is not 5 because no executable verification step (e.g., python manage.py check --deploy) or feedback loop for fixing flagged issues is provided. | 4 / 5 |
Progressive Disclosure | The single-file body has clear section headers but is ~590 lines, with substantial per-topic content (API security, file uploads, logging, CSP) inlined that would fit naturally in references/ files; no bundle files exist at all. This fits 'some structure but content that should be separate is inline' rather than 2, since headers make navigation possible. | 3 / 5 |
Total | 14 / 20 Passed |