Content
57%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is well-scaffolded for safety and offers concrete, mostly executable examples, but it stops short of a complete working document: the core workflow lives off-page with no validation checkpoints, the second reference file is undiscoverable from the root, and duplicate warnings and filler sections spend tokens without adding guidance.
Suggestions
Surface references/advanced-cloud-scripts.md directly in SKILL.md (e.g., alongside the detailed-guide link) so both bundle files are one level deep and clearly signaled.
Add a brief phase overview in the body (recon → auth testing → enumeration → escalation → reporting) with explicit validation/verification checkpoints — e.g., confirming scope before each phase and verifying findings before reporting — since the current destructive/batch operations lack any validation steps.
Trim the duplicate AUTHORIZED USE ONLY banner, replace the circular "When to Use" sentence with concrete trigger conditions, and drop the Required Knowledge list of concepts Claude already knows.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is mostly lean command lists, but it carries avoidable padding: the "AUTHORIZED USE ONLY" warning is stated twice (the opening block and again at line 24), the "When to Use" section is circular filler ("This skill is applicable to execute the workflow or actions described in the overview"), and the "Required Knowledge" list ("Cloud architecture fundamentals", "Identity and Access Management (IAM)") tells Claude what it already knows. This fits 'mostly efficient but includes some unnecessary explanation or could be tightened' rather than the trimmer anchor 4. | 3 / 5 |
Actionability | The three examples give concrete, largely executable commands (MSOLSpray invocation, `aws s3 ls`/`sync` loops, `gcloud` enumeration and SSH), and the prerequisites include real install commands. Minor gaps keep it below 5: the FireProx setup is partial, `<key>`/`<secret>`/`<api-gateway>` placeholders are left unresolved, and `pip install scoutsuite pacu` glosses over Pacu's venv-based setup. | 4 / 5 |
Workflow Clarity | The operational assessment sequence (recon, authentication testing, enumeration, escalation, extraction) is delegated entirely to detailed-guide.md rather than summarized in the body, and the body contains no validation or verification steps for operations that are destructive and batch-oriented (e.g., `aws s3 sync s3://... ./loot/`), which caps workflow clarity at 3 per the rubric. It is above anchor 2 because the prerequisites → constraints → examples progression and the pre-execution confirmation gate do provide a defined, if partial, structure. | 3 / 5 |
Progressive Disclosure | Scored against the actual bundle: references/detailed-guide.md is clearly signaled one level deep from the body, but the second bundle file, references/advanced-cloud-scripts.md, is never mentioned in SKILL.md — it is reachable only through a link inside detailed-guide.md, making it a buried second-level reference. Combined with the fully inlined examples section, this matches 'references present but not clearly signaled; content that should be separate is inline' better than anchor 4's 'minor organization gaps'. | 3 / 5 |
Total | 13 / 20 Passed |