Content
92%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
An exemplary procedure-style skill body: concrete vulnerability patterns drawn from real patch history, a classification-to-reference routing table with all referenced files verified to exist, and validation gates (confidence tiers, confirm-absent-from-all-layers, explicit zero-findings instruction) that prevent both false positives and fabricated findings. The only flaw is minor duplication between the Step 3 enforcement-chain checklist and enforcement-layers.md.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is dense and functional — the IDOR section quotes exact patterns like "Model.objects.get(id=request.data['something_id'])" and "Query includes organization_id=organization.id", with no OWASP-style teaching of concepts Claude already knows. It sits at anchor 4 rather than 5 because of minor trimmable redundancy: the 7-layer chain in Step 3 ("Authentication class → ... → Serializer") substantially duplicates the request-lifecycle list in enforcement-layers.md, and 'a check at any layer counts as enforcement' is stated twice in the body. | 4 / 5 |
Actionability | Every check gives concrete executable guidance: exact red-flag query patterns, exact safe patterns ("Uses self.get_projects() which scopes by org internally"), a 3-question IDOR trace flow, and a fully specified report template with code fences. This matches the top anchor — copy-paste-ready patterns covering the common cases. Not 4 because there are no meaningful gaps between instruction and what to actually execute. | 5 / 5 |
Workflow Clarity | The 4-step sequence (Classify → Check top-6 → Trace full enforcement chain → Report) has explicit validation checkpoints and feedback loops: the confidence table gating what gets reported ("Traced the flow, confirmed no check exists → Report with fix"), "If you cannot confirm the check is absent from every layer, mark the finding as MEDIUM, not HIGH", and "If no checks produced a potential finding, stop and report zero findings." This matches the top anchor — clear sequence with explicit validation steps and error-recovery guidance. | 5 / 5 |
Progressive Disclosure | The body acts as a clean operational overview: a classification table routes each code type to a specific reference file (all six cited files — endpoint-patterns.md, serializer-patterns.md, output-sanitization.md, token-lifecycle.md, privilege-escalation.md, enforcement-layers.md — exist in references/ and are one level deep with no further nesting), plus an explicit "Always load enforcement-layers.md" instruction. Detail is appropriately split, references are clearly signaled by exact path, and navigation is trivial. This matches the top anchor; the minor Step-3/reference duplication is scored under conciseness, not structure. | 5 / 5 |
Total | 19 / 20 Passed |