Content
47%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The command catalog is concrete and executable, but the body squanders tokens duplicating the frontmatter, provides no workflow sequencing or validation checkpoints for batch/destructive security operations, and all of its file references point to nonexistent or wrong paths. It reads as a command menu rather than a guided skill.
Suggestions
Replace the flat command catalog with a sequenced workflow (e.g., full scan -> triage findings by severity -> targeted re-checks -> remediate -> re-scan to verify the fix), with explicit validation checkpoints before and after any remediation step.
Fix the bundle paths so the Scripts table points to 'scripts/security-scan.sh' and 'scripts/cve-remediate.sh' (not '.agents/scripts/'), and either create the referenced 'docs/security-checklist.md' and 'docs/owasp-top10.md' or remove the References table.
Delete the Purpose, When to Trigger, and When to Skip sections (they restate the frontmatter description verbatim) and the redundant first command example, keeping only the Best Practices items that are specific to this skill.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The command catalog itself is lean and assumes Claude's competence, but there is substantial unnecessary content: the Purpose, When to Trigger, and When to Skip sections repeat the frontmatter description almost verbatim, the first command's 'Example' merely reprints it with one extra flag, and Best Practices is generic filler ('Use hierarchical topology for coordination') — matching anchor 3's 'mostly efficient but includes some unnecessary... could be tightened'. Not a 2 because there is no explanation of concepts Claude already knows and the core content (commands) is efficient. | 3 / 5 |
Actionability | Commands are fully executable copy-paste-ready npx invocations with concrete examples covering common cases ('security scan --depth full --output security-report.json', 'cve --scan --severity high') — matching anchor 4's 'mostly executable guidance; concrete code or commands with minor gaps'. Not a 5 because several checks (path traversal, SQL injection, XSS, threat modeling, secrets) lack examples and no output or interpretation guidance is given for any command. | 4 / 5 |
Workflow Clarity | There is no sequence at all — the body is a flat catalog of nine commands with no recommended order, no guidance on interpreting results, and no validation checkpoints, while the operations are batch/destructive-leaning (scanning a codebase, auto-remediating CVEs), which caps the score at 3 and the near-total absence of a defined workflow matches anchor 2's 'rough sequence present but many gaps; steps poorly defined; validation absent'. It does not reach 3 because not even an implicit step order or checkpoint exists in the body. | 2 / 5 |
Progressive Disclosure | Scored against the actual bundle: the Scripts table points to '.agents/scripts/security-scan.sh' and '.agents/scripts/cve-remediate.sh' but the real files live at 'scripts/', and the References table points to 'docs/security-checklist.md' and 'docs/owasp-top10.md' which do not exist anywhere — every cross-reference is broken, making navigation impossible and matching anchor 2 ('references are buried/minimal effective structure'). Section headers exist (which keeps it above 1), but it cannot score 3 or higher when following every referenced path fails. | 2 / 5 |
Total | 11 / 20 Passed |