Content
81%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A high-quality methodology skill: a clear four-step workflow with built-in validation, copy-paste templates (Mermaid DFD, STRIDE tables, output document), and concrete good/bad mitigation contrasts. The main inefficiency is re-teaching standard STRIDE categories and DFD notation that Claude already knows; everything else earns its tokens.
Suggestions
Compress or drop the STRIDE definition table and the DFD-notation glossary (Claude already knows spoofing/tampering and rectangle/circle conventions); keep only the per-element worksheet format and the judgment guidance.
If the bundle grows, move the external references list and the output document template into a references/ file and keep SKILL.md as a lean overview.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Mostly efficient, judgment-dense prose (bad-vs-good mitigation table, 'if you can't write the test, you don't have the mitigation, you have an intention', the trust-boundary test for when to skip), but the STRIDE category table and the DFD-notation list ('External entities (rectangles)... Processes (circles)...') re-explain standard security concepts Claude already knows. Not 4 because two full sections are padding Claude doesn't need; not 2 because the majority of the body adds non-obvious judgment and templates. | 3 / 5 |
Actionability | Fully actionable instruction-only guidance: an executable Mermaid DFD example, a worked STRIDE-per-element table template, the abuse-case sentence format with three worked examples, a bad-vs-good mitigation comparison with concrete specifics (5 req/min per user IP with Redis-backed counter; KMS envelope encryption with 90-day rotation), and a copy-paste output document template. These cover the common cases end-to-end. | 5 / 5 |
Workflow Clarity | The body is organized as Shostack's four questions with Steps 1-4 in strict sequence, and Step 4 is itself a validation checkpoint: coverage check ('every element... every threat... every mitigation has an owner and a deadline'), adversarial second pass to break blind spots, and trace-to-tests. Explicit validation steps and error-recovery guidance ('if you can't write the test...') match the top anchor. | 5 / 5 |
Progressive Disclosure | No bundle files exist (references/, scripts/, assets/ are absent), and the single 210-line body is well-sectioned with clear headers, no buried or nested references, and an external-reading list cleanly isolated at the end. Good structure and appropriately self-contained; not 5 because the length exceeds what the simple-skill exception rewards and a couple of sections (STRIDE reference table, external references) are natural candidates for split-out files if the bundle grows. | 4 / 5 |
Total | 17 / 20 Passed |