Content
73%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is a well-structured, highly actionable security skill with an explicit phased workflow and validation gating appropriate to destructive operations. Its main weaknesses are redundancy (a duplicated capabilities summary and repeated rule restatements) and reference files that are cited but not bundled.
Suggestions
Remove or trim the CAPABILITIES_SUMMARY/COLLABORATION_PATTERNS HTML comment, which restates content already present in the body sections.
Consolidate the persistence-first-eradication rule to a single authoritative statement plus brief cross-references rather than restating it verbatim in Core Contract, Always, Never, and Workflow.
Either bundle the referenced reference/*.md and _common/*.md files or note explicitly that they live in a shared skill system, so progressive-disclosure navigation resolves to real files.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Dense and assumes Claude's competence without explaining basics, but the CAPABILITIES_SUMMARY HTML comment largely duplicates the body and the persistence-first rule is restated ~5 times across Core Contract, Always, Never, and Workflow sections — tightening room beyond minor. | 3 / 5 |
Actionability | Concrete executable commands appear throughout ('launchctl unload', 'systemctl --user stop', 'git log --diff-filter=A --name-only', 'scan --verify-clean', 'npm ci --ignore-scripts') with exact IoC strings and paths, though the bulk of hashes and tables is deferred to reference files. | 4 / 5 |
Workflow Clarity | A clear six-phase sequence (SURVEY → SCAN → TRIAGE → ERADICATE → ROTATE → REPORT) with a purpose/action/read table, plus explicit validation (verify-clean second scan, eradication-gated rotation) and checklists (Always/Ask First/Never) for destructive operations. | 5 / 5 |
Progressive Disclosure | A clear Reference Map gives one-level-deep, well-signaled navigation with 'Read this when' guidance, but the referenced reference/*.md and _common/*.md files are not present in the bundle and the inlined Critical Patterns quick-reference duplicates detail nominally held in ioc-database.md. | 4 / 5 |
Total | 16 / 20 Passed |