Content
77%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A highly actionable, well-sequenced SSRF hunting skill with strong validation discipline (the OOB gate is a standout). Its main weaknesses are a monolithic, slightly padded structure with no progressive disclosure to bundle files, and verbose narrative/report-citation sections that inflate token cost.
Suggestions
Split the bulk reference material (Payload & Detection Patterns, Bypass Techniques, Disclosed Report Citations) into separate files under references/ and link to them from SKILL.md so the main file acts as an overview.
Compress the 'Real Impact Examples' narratives and 'Disclosed Report Citations' writeups to one-line summaries with links; drop the full root-cause prose for cases Claude already understands.
Trim restated well-known context (e.g., explanatory sentences in 'Common Root Causes') to keep only the non-obvious operational guidance.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Dense, mostly-earning operational content (payloads, bypass catalog, the OOB gate), but the long narrative 'Real Impact Examples' and full 'Disclosed Report Citations' writeups plus some restatement of well-known root causes could be tightened. | 3 / 5 |
Actionability | Copy-paste-ready curl commands, cloud-metadata payloads, a working Python redirect server, JS exfil snippets, grep/ffuf commands, and a bypass catalog fully cover the common SSRF cases. | 5 / 5 |
Workflow Clarity | The OOB gate gives an explicit sequenced workflow with validation checkpoints ('Only after a confirmed callback', 'Run the negative control', per-parameter attribution), feedback loops (retract/retest on zero callbacks, resolve flakiness), and the Gate 0 three-point checklist. | 5 / 5 |
Progressive Disclosure | Section headers and logical flow give good in-file structure, but the ~510-line SKILL.md is monolithic with no bundle files and large inlined reference tables (payloads, bypasses, report citations) that the rubric expects split into one-level-deep referenced files. | 3 / 5 |
Total | 16 / 20 Passed |