Content
50%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
Highly concrete and actionable as a per-topic pattern reference, with real code and per-area verification checkboxes. Its weaknesses are volume and structure: ~490 inline lines largely restating security fundamentals Claude already knows, with no progressive disclosure into reference files and no ordered workflow for actually executing a review.
Suggestions
Cut the body to a lean core checklist and move domain-specific deep dives (Solana wallet verification, Supabase RLS policies, CSP header recipes) into references/ files linked one level deep, e.g. 'See [blockchain.md](references/blockchain.md)'.
Add a short ordered review workflow with executable discovery commands (e.g., `grep -rE "(api[_-]?key|secret|password)" --include="*.ts"`, `gitleaks detect`, `npm audit --production`) so the model knows how to find issues, not just what to check.
Delete the duplicated verification lists: fold the per-area 'Verification Steps' into the single Pre-Deployment checklist, and trim code examples to the one that best illustrates each failure/pass pair.
Fix or remove non-executable examples — the `@solana/web3.js` `verify` import and the `@/lib/csrf` module do not exist, which undermines the copy-paste reliability of the skill.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | At ~490 lines, the body extensively re-teaches standard security knowledge Claude already has — JWT-in-httpOnly-cookies, parameterized queries, DOMPurify, express-rate-limit, npm audit — with several padded sections and redundancy (per-area 'Verification Steps' duplicated almost verbatim by the 'Pre-Deployment Security Checklist'). It is above score 1 because there is no conceptual filler prose (no 'what is XSS' explanations), but noticeably below the midpoint because most of the volume adds little beyond Claude's existing knowledge. | 2 / 5 |
Actionability | Nearly every section gives copy-paste-ready TypeScript/SQL/bash (zod schemas, Supabase RLS policies, Set-Cookie headers, npm audit commands) plus checkbox verification steps. Not a 5 because some examples are not actually executable: `import { verify } from '@solana/web3.js'` (no such export — wallet verification needs tweetnacl), the invented `@/lib/csrf` module, and a `Transaction` object with nonexistent `.to`/`.amount` fields. | 4 / 5 |
Workflow Clarity | There is a usable structure — activation triggers, ten themed checklist areas, a testing section, and a final pre-deployment checklist — but no sequenced process for conducting a review (how to find hardcoded secrets, e.g. grep/secret-scanning commands, in what order to check things). It matches 'steps/checks listed but validation gaps; checkpoints implicit' rather than score 4, which would require an explicit ordered review workflow with checkpoints. | 3 / 5 |
Progressive Disclosure | No bundle files exist (references/, scripts/, assets/ are absent), so everything is inline in one 490-line file. Section headers are clear and the structure is not minimal (so above score 2), but specialty content that clearly belongs in separate reference files — the Solana blockchain section, Supabase RLS SQL — is inlined in a general-purpose checklist, matching 'some structure but content that should be separate is inline'. | 3 / 5 |
Total | 12 / 20 Passed |