Content
88%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A well-crafted procedural skill body: concrete commands, deterministic rules, and workflows with genuine validation gates ('do not commit' unless steps 1–4 pass). The residual gaps are minor — slight redundancy around the CVE contrast/exclusion rationale and content that is just past the length where splitting out a reference file would pay off.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is lean and almost every token carries repo-specific information Claude cannot know (registry layout, id allocation, tag protocol). Minor over-explanation keeps it below anchor 5: the CVE contrast paragraph ('Unlike a CVE (which describes something that was once broken)') and the trailing 'good test' heuristic partly restate the point already made in 'When NOT to use this convention'. Not 3 because none of it is generic background knowledge. | 4 / 5 |
Actionability | Guidance is fully executable for an instruction-only skill: copy-paste-ready commands ('grep -rn GRIDA-SEC-<id> .' and the test-discovery grep with '--include=*test*'), a deterministic id-allocation rule ('find the highest existing GRIDA-SEC-NNN, use NNN+1'), and a prescribed four-section SECURITY.md entry shape with example tag formats ('// GRIDA-SEC-NNN: rule 2 — fail closed'). Not 4 because no key detail is left for the reader to fill in. | 5 / 5 |
Workflow Clarity | Both multi-step processes are explicitly sequenced with validation checkpoints and a real feedback loop: the pre-commit review requires re-reading each SECURITY.md entry, walking each numbered enforcement step against the diff, verifying tags survive renames, and gating on 'If you cannot satisfy steps 1–4, do not commit. Either revert the change, or explicitly amend the SECURITY.md entry'. This matches the anchor 5 pattern of sequence + explicit validation + error-recovery path. | 5 / 5 |
Progressive Disclosure | Sections are well-organized (meaning, working with tagged code, mandatory review, adding a new id, exclusions) and the body is appropriately self-contained for a convention skill with no bundle files. Below 5 because at ~95 lines the 'Adding a new id' procedure and the exclusions section are each substantial enough to live in a reference file, and the deep relative link ('../../../supabase/AGENTS.md#rpc-role-contract') is navigation a reader must resolve unaided. Not 3 because structure and signaling are otherwise clear and one level deep. | 4 / 5 |
Total | 18 / 20 Passed |