Content
85%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A well-engineered operational runbook: an ordered preflight-to-handoff flow with genuine validation gates, copy-paste commands with expected outputs, and crisp delegation of detail to per-mode reference files. Its one material defect is that the bundle does not ship the referenced files — SINGLE_MODE.md, QUEUE_MODE.md, SECURITY.md, CREDENTIAL_OVERWRITES.md, and DAY2.md are cited (and steps depend on them for the openssl commands and Day-2 handoff) but absent, so the progressive-disclosure structure breaks at its first hop.
Suggestions
Ship the five referenced files (SINGLE_MODE.md, QUEUE_MODE.md, SECURITY.md, CREDENTIAL_OVERWRITES.md, DAY2.md) in the bundle — every pointer in the body currently dead-ends, and step 4 depends on SECURITY.md for the openssl secret-generation commands it defers to.
Inline the minimal openssl commands for N8N_ENCRYPTION_KEY (and POSTGRES_PASSWORD in queue mode) directly in step 4 so the launch-critical path survives even if a reference file is missing.
Trim the "What NOT to do" section to only novel items — "Don't publish 5678/5432/6379", "Don't put secrets in docker-compose.yml or the Caddyfile", and "Don't reuse another instance's encryption key" restate Rule 1 nearly verbatim.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Largely lean and operational — it assumes competence and spends tokens only on n8n-specific gotchas ("a leftover placeholder becomes the literal password and Postgres/n8n fail to connect", "an exposed un-owned instance is a race"), which Claude cannot know a priori. It misses a 5 because of redundancy: the "What NOT to do" section restates Rule 1 items nearly verbatim ("Don't publish 5678/5432/6379", "Don't put secrets in docker-compose.yml or the Caddyfile", "Don't reuse another instance's encryption key") already covered above. | 4 / 5 |
Actionability | Fully executable commands throughout, copy-paste ready: "curl -s ifconfig.me", "dig +short <fqdn>", "ssh <target> 'cat > <DATA_FOLDER>/docker-compose.yml' < assets/docker-compose.single.yml", "grep REPLACE_WITH_ .env", "docker compose exec n8n wget -qO- http://localhost:5678/healthz", "curl -fsS --retry 5 --retry-delay 10 https://<fqdn>/healthz", and the env-parity diff with process substitution. Each step states exactly what to run and what the expected output is ("{'status':'ok'}"). | 5 / 5 |
Workflow Clarity | A clear 8-step preflight→handoff sequence with explicit validation checkpoints and feedback loops: DNS mismatch → "stop... Have the user create the A record, wait for it to propagate, then continue"; a hard gate before launch ("grep REPLACE_WITH_ .env must return nothing — Before launching, confirm none are left unset"); and a verify step that separates failure modes (internal healthz vs. "cert is still pending, not that n8n is down") with retry logic, culminating in "don't declare success without this". The destructive/batch cap does not apply — validation is present and thorough. | 5 / 5 |
Progressive Disclosure | The structure and signaling are excellent — a Reference files section enumerates each file with a one-line scope, and inline pointers land at the exact section needed ("the modules section of QUEUE_MODE.md"). But scored against the actual bundle, five of the six referenced files are missing: SINGLE_MODE.md, QUEUE_MODE.md, SECURITY.md, CREDENTIAL_OVERWRITES.md, and DAY2.md do not exist in the bundle (only the six assets/ templates are present). Navigation dead-ends for all per-mode and security detail, including the openssl commands step 4 depends on ("SECURITY.md has the commands") — this is worse than the "minor organization gaps" of the 4 anchor, though better than the 2 anchor since the overview itself is well organized and all asset paths resolve. | 3 / 5 |
Total | 17 / 20 Passed |