Content
57%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A comprehensive, actionable security reference with strong UNSAFE→SAFE code examples and good structure, but it is a long monolithic document that inlines material (notably the 20-language quirks) that would be better placed in one-level-deep reference files, and it lacks an explicit review workflow with validation checkpoints.
Suggestions
Move the 'Language-Specific Security Quirks' section (and optionally the ASVS levels / agentic AI risk tables) into reference files (e.g., references/language-quirks.md, references/agentic-ai.md) and replace the inline bulk with one-level-deep pointers like 'See [language-quirks.md](references/language-quirks.md) for the language you are working in'.
Add a short explicit review workflow at the top — e.g., 1) Identify the language/framework context, 2) Run the applicable checklist, 3) For each finding, propose a SAFE fix and verify it addresses the vulnerability — to add validation checkpoints and lift workflow clarity.
Trim redundant framing lines (e.g., the 'Deep Security Analysis Mindset' prose overlaps the language-quirks section) to tighten the token budget.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is dense and format-efficient (tables, terse UNSAFE/SAFE pairs, checklists) and avoids explaining basic concepts, but at ~530 lines the inlined 20-language-quirks reference and broad ASVS/agentic tables exceed a lean token budget and could be tightened or externalized; not a 4 because several sections pad the overview beyond what the trigger needs. | 3 / 5 |
Actionability | Provides many concrete, executable UNSAFE→SAFE code pairs across SQL injection, command injection, password storage, access control, error handling, and per-language pitfalls, plus specific checklist items and named mitigations; not a 5 because some guidance remains checklists rather than fully copy-paste-ready commands, though that is appropriate for a review skill. | 4 / 5 |
Workflow Clarity | As a reference/checklist skill it provides ordered checklists and a 'When to Apply This Skill' section, but there is no explicit multi-step review workflow with validation checkpoints (e.g., run review → triage findings → confirm fix); the absence of a validate→fix→retry feedback loop caps it at 3 even though it is not a destructive-batch skill. | 3 / 5 |
Progressive Disclosure | The body is well-organized with clear section headers and tables, but no bundle files (references/scripts/assets) exist and roughly 250 lines of language-specific quirks plus the bulk ASVS/agentic tables are inlined in SKILL.md rather than split into one-level-deep reference files with clear navigation; not a 4 because content that clearly belongs in separate files is inline and no references are signaled. | 3 / 5 |
Total | 13 / 20 Passed |