Content
60%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A lean, well-sequenced body with concrete explore/verify commands, but its progressive disclosure is broken: the Fix step and Rules section defer to files that are missing from the bundle entirely. The skill reads as an index to a detail layer that does not exist, and the verify block includes a questionable 'bun i --yarn' command with no failure-recovery guidance.
Suggestions
Create the referenced rule files (e.g., rules/vuln-direct-deps.md, rules/vuln-transitive-deps.md) with the concrete fix patterns, or inline those patterns in SKILL.md — as written, the core 'Fix' step has no executable content.
Make reference paths consistent (the Quick Reference table cites bare filenames while the Rules section cites a 'rules/' directory) so navigation is unambiguous.
Verify the 'bun i --yarn' command is correct for the target project and add a feedback loop to the Verify step (e.g., 'if any check fails, fix and re-run before proceeding').
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is lean, assumes Claude's competence, and explains nothing Claude already knows. It is not 5 because the opening line ('Resolve npm dependency vulnerabilities detected by Snyk.io security scans.') largely duplicates the description, and the rules are pointed to three times (Quick Reference table, 'See rules for specific fix patterns', 'See `rules/` directory'). | 4 / 5 |
Actionability | Some concrete, executable guidance exists ('npm view <package> versions --json', the verify command block), but the core 'Fix' step contains only 'See rules for specific fix patterns' — and those rule files are absent from the bundle, so the key executable detail is missing. The verify block's 'bun i --yarn' is also a dubious command. Not 2 because Explore and Verify do give specific runnable commands. | 3 / 5 |
Workflow Clarity | The Assess → Explore → Fix → Verify sequence is clearly staged with an explicit validation block ('All must pass'), and Explore's inputs are well enumerated. It is not 5 because there is no error-recovery feedback loop — what to do when type:check/lint/build/test fails is left implicit. | 4 / 5 |
Progressive Disclosure | The structure is well intended (Quick Reference table mapping fix types to one-level-deep rule files), but the referenced files ('vuln-direct-deps.md', 'vuln-transitive-deps.md', the 'rules/' directory) do not exist anywhere in the bundle, leaving navigation dangling and the skill's core detail layer absent. Path references are also inconsistent (bare filenames vs. 'rules/ directory'). | 2 / 5 |
Total | 13 / 20 Passed |