Content
78%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A highly actionable hunting skill with concrete payloads, commands, and a validation gate that gives Claude exactly what to do. Its main weakness is structure: all content lives in one large SKILL.md with no bundle files or one-level-deep references, hurting progressive disclosure.
Suggestions
Split the bulky reference material into bundle files — e.g. references/payloads.md for the payload trees, references/waf-bypass.md for the bypass catalog, and references/cve-citations.md for the disclosed-report list — then link to them one level deep from SKILL.md.
Tighten or trim the 'Crown Jewel Targets' and 'Real Impact Examples' narrative sections, keeping only the operational signals (URL patterns, asset types) and moving the illustrative prose into a reference file.
Add inline per-step validation cues within the 'Step-by-Step Hunting Methodology' (e.g. 'confirm before proceeding') rather than consolidating all validation in the separate Gate 0 section.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Largely efficient with dense code blocks, payloads, and command lists rather than explaining concepts Claude already knows, though the 'Crown Jewel Targets' and 'Real Impact Examples' scenarios add narrative/motivational padding that could be trimmed. | 4 / 5 |
Actionability | Fully copy-paste ready: exact sqlmap flags (--level=3 --risk=2), curl time-based detection commands, grep patterns for JS source hunting, Burp Intruder column-enumeration lists, and concrete payloads for every technique family. | 5 / 5 |
Workflow Clarity | A clearly sequenced 10-step methodology plus a 'Gate 0 Validation' section with explicit pre-report checkpoints and proof requirements (validation present, so the destructive/batch cap does not apply), though per-step validation checkpoints are consolidated in Gate 0 rather than inline at each step. | 4 / 5 |
Progressive Disclosure | Well-structured with clear section headers, but the ~420-line body is monolithic — no references/scripts/assets bundle exists and large blocks (full CVE citation list, WAF-bypass catalog, payload trees) that would benefit from one-level-deep reference files are fully inlined. | 3 / 5 |
Total | 16 / 20 Passed |