Content
57%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body delivers genuinely actionable, code-heavy Django security guidance and is well sectioned, but it is monolithic: duplicated header/CSP content, two competing file-validation implementations, and no progressive disclosure into reference files. It reads as a reference dump rather than an overview with a navigable structure, and it lacks a sequenced review workflow.
Suggestions
Consolidate the three overlapping sections on security headers and CSP (production settings, 'HTTP Headers', and 'Security Headers') into one canonical block to remove duplication.
Split topical deep-dives (file upload security, API security, RBAC) into reference files under references/ and keep SKILL.md as a lean overview with one-level-deep, clearly signaled links.
Add a sequenced workflow — e.g., an ordered security-review procedure that walks the Quick Security Checklist with validation checkpoints — instead of presenting purely parallel topic sections.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is mostly code with little prose padding, but it contains notable duplication — security headers/CSP settings appear in three separate sections and there are two parallel file-validation implementations — plus restatements of Django defaults Claude already knows. It fits 'mostly efficient but includes some unnecessary content that could be tightened' more than the severely padded 2 anchor. | 3 / 5 |
Actionability | Concrete, mostly copy-paste-ready code throughout (production settings, custom user model, validators, DRF permissions, throttling), with minor gaps: fragments use undefined names ('ImproperlyConfigured' and 'Response' without imports, 'User' referenced before it is defined), keeping it below the fully-executable 5 anchor. | 4 / 5 |
Workflow Clarity | The body is a well-organized topical reference with a 'When to Activate' list and a closing checklist, but it presents no sequenced workflow (e.g., an ordered security-review or deployment-hardening procedure) and no validation checkpoints, matching the 'structure present but sequence/checkpoints missing' level rather than 4. | 3 / 5 |
Progressive Disclosure | Section headers are clear and consistent, but ~640 lines of reference material are entirely inlined in SKILL.md with no references to separate files — content that clearly belongs in reference files (API security, file upload security, RBAC) is inline. This sits between the minimal-structure 2 anchor and the well-split 4 anchor. | 3 / 5 |
Total | 13 / 20 Passed |