Content
81%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is a highly actionable, well-sequenced security review workflow with executable commands, explicit validation feedback loops, and a deliberate two-file reference split. Its main weakness is repetition: the report-shape invariant and the comment-is-a-claim rule are each stated multiple times, and the inline checklist mass keeps the SKILL.md from being a lean overview of its own references.
Suggestions
State the report-shape invariant once (Step 0) and have later sections reference it in one line instead of re-explaining it at Step 2 and the final check.
Fold the Step 2 "a comment is a claim, not a control" rule and JWT rule 3 ("a comment arguing for the gap does not close it") into a single statement, since they make the same point.
Trim rhetorical framing ("however good the analysis inside it", "that is the one way this run fails outright") — the operative rule lands without the emphasis.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Most content is repo-specific knowledge Claude cannot infer (grep routing table, OSN conventions, sibling-verb procedure), but the skeleton/shape invariant is stated three times (Step 0, mid-Step 2, final check), "a comment is a claim, not a control" appears twice, and rhetorical padding ("however good the analysis inside it") could be trimmed — anchor 3, not 4, because the repetition is noticeable. | 3 / 5 |
Actionability | Fully copy-paste-ready throughout: the heredoc report skeleton, `git config --get branch.$(git branch --show-current).gh-merge-base` base resolution, the exact grep pattern table, the `grep -c` shape checks, the exact finding template, and the numbered JWT-options and sibling-verb procedures — matching the anchor-5 example of executable commands covering the common cases. | 5 / 5 |
Workflow Clarity | Steps 0→1→2 are clearly sequenced with an explicit mid-run validation checkpoint ("It must print 4… restore the 4 headings, put the finding back under the right one") and a final verification pass with recovery guidance — a full validate→fix→re-check loop matching anchor 5. | 5 / 5 |
Progressive Disclosure | Two one-level-deep references (references/checklists.md, references/compliance.md) exist as real files, are clearly signaled, and each carries an explicit when-to-open condition; however the body itself is ~280 lines of inline checklists rather than a lean overview pointing at them, fitting anchor 4 rather than 5. | 4 / 5 |
Total | 17 / 20 Passed |