Content
56%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is strong on executable commands and the adversarial workflow includes a genuine validation loop, but it is padded with concepts Claude already knows (OWASP category enumeration, STRIDE definitions) and duplicated usage examples. Referenced detail files are absent from the bundle, so the skill reads as an inlined monolith rather than an overview pointing to references.
Suggestions
Remove or move the OWASP Top 10 category list and the STRIDE threat table into a reference file — Claude already knows both frameworks; keeping them inline wastes context.
Consolidate the three separate orchestrate.sh example blocks (Usage, Adversarial Mode, Advanced Options) into a single usage section to eliminate repetition.
Ship the referenced bundle files (skills/blocks/fable5-prompting.md, agents/personas/security-auditor.md) or remove the dangling references, so every cited path resolves.
Tighten the Model Selection Caveat section — its dense policy text mixes time-sensitive model IDs with routing rules that could be shortened to the decision rule plus the reference pointer.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body inlines concepts Claude already knows — the full OWASP Top 10 category list and a six-row STRIDE table ('Spoofing | Can an attacker impersonate a user or component?') — and repeats orchestrate.sh usage examples three times (Usage, Adversarial Mode, Advanced Options). This is noticeably verbose with several padded sections, below the 'mostly efficient' midpoint. | 2 / 5 |
Actionability | Provides concrete, executable commands throughout — 'git log --all -p -S 'AKIA' --pickaxe-regex', 'orchestrate.sh squeeze --loop --quality 100', the CI/CD find command. Not a 5 because the CI/CD 'Check for dangerous patterns' block is descriptive commentary rather than executable checks, leaving minor gaps. | 4 / 5 |
Workflow Clarity | The squeeze workflow is a clearly sequenced 4-phase cycle (Blue Team, Red Team, Remediation, Validation) with an explicit feedback loop — 'Antigravity re-tests, confirms fixes or fails' — and the mode auto-escalation rules are unambiguous. Not a 5 because Quick mode lacks report-format or follow-up guidance and the document's duplicated structure scatters the two entry points. | 4 / 5 |
Progressive Disclosure | No bundle files exist, yet the body references 'skills/blocks/fable5-prompting.md' and 'agents/personas/security-auditor.md' — paths that do not resolve in this bundle. Inline reference material (OWASP list, STRIDE table, git-history commands) should live in separate files. Some structure exists via sections and tables, but organization into one-level-deep references is absent. | 3 / 5 |
Total | 13 / 20 Passed |