Content
57%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A well-organized, genuinely actionable guide to Burp Suite testing with an exemplary authorization gate, but it is overweight for a single SKILL.md: generic payloads, shortcut tables, troubleshooting, and examples should be split into reference files, and the batch/offensive phases need explicit validation checkpoints. The workflow cap and the inline-bloat together hold the content score to the middle of the scale.
Suggestions
Move the payload library, keyboard shortcuts, worked examples, and troubleshooting into references/ files (e.g., references/payloads.md, references/troubleshooting.md) linked one level deep from SKILL.md.
Add explicit validation checkpoints to the risky phases: before launching an Intruder attack, verify the target is in scope and rate-limited; after scans/attacks, verify findings against false positives before reporting.
Delete or trim content Claude already knows — the canonical SQLi/XSS/path-traversal payload list and generic explanations like "Scope Benefits" — to tighten token efficiency.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is mostly tight, procedural, and UI-path-driven, but it spends tokens on things Claude already knows: a "Common Testing Payloads" block of canonical SQLi/XSS/traversal one-liners, generic keyboard-shortcut and editions-comparison tables, and advisory sections like "Scope Benefits". These are unnecessary explanations/padding rather than skill-specific knowledge, matching the anchor for "mostly efficient but includes some unnecessary explanation". | 3 / 5 |
Actionability | Guidance is concrete and directly executable for a GUI-tool skill: exact navigation paths ("Proxy > Intercept tab", "right-click > Send to Intruder"), a worked HTTP request/response example with a concrete before/after body, a filled-in Intruder payload-position example ("username=§admin§&password=§password§"), and scan-configuration tables. It falls short of 5 because several phases (e.g., scan configuration, response analysis) describe what to look at rather than giving specific parameter values or commands. | 4 / 5 |
Workflow Clarity | The six-phase workflow is clearly sequenced with numbered steps, and the authorization confirmation gate at the top is an excellent upfront checkpoint. However, the rubric caps workflow clarity at 3 for batch/destructive operations lacking validation, and the Intruder credential-testing and automated-scan phases include no validate/verify/fail-fast checkpoints — e.g., no step to confirm scope and rate limits before launching an attack, or to verify findings against false positives before reporting. | 3 / 5 |
Progressive Disclosure | The body has clear section headers and a logical overview-to-detail flow, but it is a ~400-line monolith with no bundle files and no references: content that clearly belongs in separate reference files (payload library, keyboard shortcuts, troubleshooting, and the three worked examples) is all inlined. This matches the anchor "some structure but could be better organized; content that should be separate is inline". | 3 / 5 |
Total | 13 / 20 Passed |