Content
88%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A highly actionable, well-sequenced skill body with executable commands, validation-gated triage, and destructive-operation safeguards. The relative weak spots are mild framing prose and a monolithic single-file structure with no progressive disclosure into bundle files.
Suggestions
Trim the editorial framing sentences (e.g., "the part people forget", the "Most secret leaks aren't 'we forgot to redact'..." opener) to tighten conciseness without losing operational value.
Consider moving the provider-key-prefix grep library and/or the build-artifact leakage list into a references/ file referenced from SKILL.md, so the body stays a lean overview and progressive disclosure can reach the top anchor.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is information-dense and assumes Claude's knowledge (no explaining what a secret or git is), with every section delivering operational value; a few framing sentences ("the part people forget", "Most secret leaks aren't 'we forgot to redact'...") are light padding that could be trimmed, keeping it just below the lean anchor. | 4 / 5 |
Actionability | It provides copy-paste-ready, executable grep patterns, git history/trufflehog/gitleaks/bfg commands, docker history checks, and provider verification calls (aws sts get-caller-identity, stripe balance retrieve) that cover the common cases concretely. | 5 / 5 |
Workflow Clarity | The 7-step triage workflow has explicit validation checkpoints ("Verify it's live — ... don't assume", rotate-before-revoke, rotate first then history-rewrite), and the destructive history-rewrite operation is gated by an explicit coordination/confirmation requirement, satisfying the destructive-operation validation cap. | 5 / 5 |
Progressive Disclosure | Content is organized into clear Part 1 / Part 2 / Output Format / Boundaries / References sections with well-signaled inline cross-references to sibling skills; with no bundled reference files present the operational detail is appropriately inline, leaving only minor organization gaps versus a fully split structure. | 4 / 5 |
Total | 18 / 20 Passed |