Content
85%Scale 1-3Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
This is a well-structured, highly actionable security audit skill with clear methodology sequencing and appropriate progressive disclosure to reference files. Its main weakness is verbosity — the 'Rationalizations to Reject' section, extensive 'When to Use/NOT to Use' lists, and explanatory prose about why certain patterns are dangerous add token overhead that could be trimmed since Claude can infer these rationales. The workflow clarity and actionability are excellent, with concrete commands, precise field names, and structured output formats.
Suggestions
Compress the 'Rationalizations to Reject' section into a compact table (rationalization | why wrong) rather than paragraph-per-item format to save ~40% of that section's tokens.
Trim the 'When to Use' and 'When NOT to Use' sections — Claude can infer appropriate usage from the methodology itself; consider reducing to 2-3 bullet points each or removing entirely.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The skill is thorough but verbose in places. The 'Rationalizations to Reject' section, 'When to Use'/'When NOT to Use' lists, and explanatory prose add significant token overhead. Some sections like URL parsing and bash safety rules are well-structured but could be more compact. The skill explains concepts Claude would understand (e.g., what pull_request_target does, what sandboxes are) rather than just stating the rules. | 2 / 3 |
Actionability | The skill provides highly concrete, executable guidance: specific `gh api` commands with exact flags and jq expressions, precise YAML field names to check per action type, a structured detection methodology with specific pattern-matching rules, and detailed report formatting instructions. The action reference table, security context capture fields, and vector detection heuristics are all specific and actionable. | 3 / 3 |
Workflow Clarity | The 5-step methodology (Discover → Identify → Capture → Analyze → Report) is clearly sequenced with each step building on the previous. Step 0 handles mode determination with error handling. Cross-file resolution has a depth limit. The reporting step includes severity judgment criteria, data flow trace rules, and clean-repo output handling. Validation checkpoints are present (e.g., 'If no workflow files found, stop'; 'If no AI action steps found, stop'). | 3 / 3 |
Progressive Disclosure | The skill maintains a clear overview structure with well-signaled one-level-deep references to detailed materials: action-profiles.md, foundations.md, individual vector files (vector-a through vector-i), and cross-file-resolution.md. The main SKILL.md provides the methodology overview and quick-check table while deferring detection heuristics and action-specific details to reference files. Navigation is clear via the vector table and 'Detailed References' section. | 3 / 3 |
Total | 11 / 12 Passed |