Content
46%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is a compact, clearly navigable index with a sensible one-level progressive-disclosure design, but it is undermined by broken references (all six target files are absent from the bundle), decorative persona framing that pads the token budget, redundant routing sections, and a complete absence of validation/verification checkpoints for risky security operations. As written, following any instruction in this skill leads to a dead end.
Suggestions
Ship the six referenced manuals (pentest.md, code-audit.md, red-team.md, blue-team.md, threat-intel.md, vuln-research.md) in the bundle, or remove/collapse the links until they exist — the entire skill currently routes to nothing.
Merge the '快速选择' section into the '秘典矩阵' table to eliminate the duplicated routing rows and persona labels, and strip decorative framing ('三脉道统', '化身') that adds tokens without instruction.
Add validation checkpoints appropriate to the domain — e.g. confirm engagement scope/authorization before offensive steps, and verify findings (reproduced PoC, corroborated detection) before reporting — to lift workflow clarity above 3.
Resolve the dangling '紫霄脉' reference in '攻防协同', which names a lineage that appears nowhere else in the matrix.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is short and table-based, but a noticeable share of tokens is spent on decorative persona framing — "三脉道统", "秘典矩阵", per-row "化身" labels, and emoji sigils — and the "快速选择" section substantially repeats the 秘典矩阵 table (e.g. 'Web/API 渗透 → pentest.md — 🗡 破阵化身' appears in both). These are unnecessary explanations/redundancy that could be trimmed, matching 'mostly efficient but includes some unnecessary explanation'. | 3 / 5 |
Actionability | The routing guidance is concrete (each task maps to a named file: 'Web/API 渗透 → pentest.md', '检测规则 → blue-team.md'), but it is incomplete: the body contains no executable commands, no code, no concrete technique steps, and — critically — none of the six referenced files (pentest.md, code-audit.md, red-team.md, blue-team.md, threat-intel.md, vuln-research.md) exist in the bundle, so every pointer dead-ends. This fits 'some concrete guidance but incomplete; missing key details'. | 3 / 5 |
Workflow Clarity | The kill-chain and defense-chain diagrams (侦察 → 武器化 → 投递 → 利用 → 安装 → C2 → 行动; 预防 → 检测 → 响应 → 恢复) present rough conceptual sequences, and the routing flow (pick task → open the matching manual) is a coherent single action, but there are no validation checkpoints anywhere and no error-recovery guidance — e.g. nothing on verifying scope/authorization before offensive actions or validating findings before reporting. That matches 'steps listed but validation gaps; checkpoints missing or implicit'. | 3 / 5 |
Progressive Disclosure | The design intent is good — a lean one-level index pointing to six per-domain manuals — but scoring against the actual bundle structure, the referenced files do not exist: there is no references/, scripts/, or assets/ directory, so all six links ([pentest](pentest.md), [code-audit](code-audit.md), [red-team](red-team.md), [blue-team](blue-team.md), [threat-intel](threat-intel.md), [vuln-research](vuln-research.md)) are broken. A well-signaled index whose every target is missing leaves the skill with minimal effective structure, matching 'minimal structure; references…' at the low anchor rather than a 3, where references at least resolve to real content. | 2 / 5 |
Total | 11 / 20 Passed |