Content
71%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A highly actionable, information-dense skill body dominated by executable commands, real secret names, and explicit safety rules for writes. Its weaknesses are the absence of any progressive disclosure (all account history and troubleshooting inlined in one file) and a few executable gaps such as a comment-only lease-revocation section and an inconsistent `secrets lease` export form.
Suggestions
Move dated troubleshooting logs (PIN OAuth note, auth verification, bookmark caveat) and per-account secret lists into a references file (e.g. references/accounts.md) and link them from SKILL.md.
Replace the comment-only "Revoke leases after use" section with the actual revocation command and lease-id capture pattern.
Reconcile the `secrets lease` usage: either document its JSON output in the export form (e.g. pipe through jq) or use one consistent helper.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is dense and operational — secrets lists, executable scripts, rate limits, and hard rules with almost no padding — but dated troubleshooting entries ("PIN OAuth note, 2026-06-28", "Auth verification, 2026-06-28") and duplicated per-account blocks sit outside any 'old patterns'/'deprecated' section and could be trimmed. This matches the 4 anchor (efficient, minor instances that could be trimmed) rather than 3, since the dated material is a small fraction of otherwise lean content. | 4 / 5 |
Actionability | Nearly everything is copy-paste ready: the bearer-derivation Python script, curl search calls with full query strings, the OAuth1Session pattern, common API calls with real params, and `shitrat x` / `agent-browser` commands. Minor gaps keep it at 4: the "Revoke leases after use" section contains only a comment with no executable command, and `export CK=$(secrets lease x_consumer_key)` contradicts the other script, which parses JSON from `secrets lease` output. | 4 / 5 |
Workflow Clarity | The reply/context pass is a clear numbered 5-step sequence, and write operations have explicit checkpoints (`--dry-run` is free, `--yes` is a write, approval gates for tweets and article creates, 401 → refresh before retry). It falls short of 5 because there are no explicit validate-fix-retry loops for API call failures, and short of nothing below — sequence and most checkpoints are present. | 4 / 5 |
Progressive Disclosure | A ~250-line monolithic SKILL.md with no bundle files at all; account-specific secrets, PIN-OAuth troubleshooting history, and per-account details that clearly belong in separate reference files are inlined. Section headers are decent, matching the 3 anchor (some structure, content that should be separate is inline) rather than 2, since navigation is not impossible and sections are clearly labeled. | 3 / 5 |
Total | 15 / 20 Passed |