Content
57%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A technique-rich catalog with strong concrete payloads and a recognizable five-step workflow, but it reads as a reference dump rather than a guided skill: no validation checkpoints, monolithic single-file structure, and duplicated/filler sections that inflate token cost. Splitting reference material into bundle files and adding finding-verification steps would lift most dimensions.
Suggestions
Move the Tools Reference, Common API Vulnerabilities Checklist, and Quick Reference tables into a references/ file and link them from SKILL.md, keeping the body as a concise workflow overview.
Add verification checkpoints to the workflow (e.g. after Step 1 confirm discovered endpoints; after Step 3 confirm the IDOR response actually returns another user's data before reporting).
Delete the filler 'When to Use' sentence and the 'Purpose' section that duplicates the description, and consolidate the IDOR techniques that currently appear in three places.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The payload and command listings are dense and mostly lean, but the 'Purpose' section repeats the frontmatter description verbatim, the 'When to Use' section is pure filler ('This skill is applicable to execute the workflow or actions described in the overview.'), and IDOR material is duplicated across Core Workflow, Quick Reference, and Examples. | 3 / 5 |
Actionability | Provides concrete, mostly ready-to-use payloads and commands (JSON SQLi payloads, GraphQL introspection queries with a curl example, 403 bypass path list), but several blocks are notation rather than executable commands (e.g. 'GET /api/users/1234 → GET /api/users/1235' and bare path lists inside bash blocks). | 4 / 5 |
Workflow Clarity | The 'Core Workflow' gives a clear Step 1–5 sequence, but there are no verification checkpoints between steps (no confirmation that recon found endpoints, no guidance on validating a suspected IDOR/SQLi finding before reporting), and the exploitation operations would benefit from explicit validation given data extraction is involved. | 3 / 5 |
Progressive Disclosure | Sections and tables are well organized and easy to navigate, but the skill is a 440-line monolith with no bundle files; the 20-row Tools table, vulnerability checklists, and quick reference clearly belong in separate reference files that SKILL.md should point to. | 3 / 5 |
Total | 13 / 20 Passed |