Content
70%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A strong, concrete security skill with exemplary workflow validation (explicit stop conditions, fail-loud error handling, remediation paths) and highly actionable patterns. Its weaknesses are redundancy between the Patterns, Examples, and Anti-Patterns sections, a sample scan script that omits its own most important regex, and a fully-inlined ~200-line body that could offload reference material to bundle files.
Suggestions
Make the sample PowerShell scan list match the full regex table — the omitted connection-string pattern (`(?:postgres|mysql|mongodb)://[^@]+@...`) guards the exact violation the skill's own ✗ example demonstrates.
Trim the Anti-Patterns entries that restate rules already stated verbatim in Patterns (e.g. the .env-schema and scan-before-commit duplicates) to cut redundancy.
Move the regex scanning table, example transcripts, and remediation runbook into references/ files (e.g. references/patterns.md, references/remediation.md) with clear one-level links from SKILL.md.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Mostly operational content that earns its tokens (regex table, procedures, templates), but the Anti-Patterns section re-states rules already given (e.g. reading .env "just to check the schema" repeats the earlier NEVER assume line) and the multi-transcript Examples could be tightened. This is "could be tightened" territory (anchor 3), more than minor trimming (anchor 4). | 3 / 5 |
Actionability | Guidance is highly concrete: exact file names, a full regex scanning table (`AKIA[0-9A-Z]{16}|aws_secret_access_key=[^\s]+`), copy-paste report templates, and commands (`git reset HEAD <file>`). Not anchor 5 because the sample PowerShell scan list includes only 3 of the 7 patterns and omits the connection-string regex — even though a leaked `DATABASE_URL=postgres://...` connection string is the skill's own canonical violation example — leaving a real gap for an implementer. | 4 / 5 |
Workflow Clarity | The Scribe pre-commit workflow is a clear numbered sequence with explicit validation checkpoints and stop conditions ("Scan all staged files", "If secrets detected: STOP the commit", "Run validation AFTER staging, BEFORE calling git commit", "Exit with error"), and the remediation runbook adds error-recovery paths and a do-not-proceed gate. This matches anchor 5, including the destructive-operation validation requirement. | 5 / 5 |
Progressive Disclosure | No bundle files exist and all ~200 lines live in SKILL.md. Section headers are well organized, but the regex table, full example transcripts, and the remediation runbook are content that could sit in separate reference files — "some structure but could be better organized" (anchor 3) rather than anchor 4, since there are no references at all. | 3 / 5 |
Total | 15 / 20 Passed |