Content
77%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A well-structured, actionable skill with an exemplary phased workflow and verification loop, held back by a progressive-disclosure failure: two reference files exist in the bundle but are never linked from the body, and representative fixes are inlined instead. Conciseness and actionability are good with only minor trimming opportunities.
Suggestions
Add explicit links in Phase 4 to the existing bundle files, e.g. "Terraform: see [terraform-security-patterns.md](references/terraform-security-patterns.md)" and "Kubernetes: see [kubernetes-security-patterns.md](references/kubernetes-security-patterns.md)", so the detailed patterns are discoverable.
Replace the inlined remediation snippets in Phase 4 with one representative example plus the reference links, keeping SKILL.md as an overview and moving the per-resource fix catalog entirely into the references.
Add trigger terms for the supported formats the description omits (.tf files, K8s/Helm, Serverless) so the description matches the body's actual coverage.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is largely lean — tables, parameterized scan invocations, and ready fixes with no concept explanations of what Terraform or Kubernetes is. Score 4 rather than 5 because the Phase 4 remediation snippets (S3 public access block, secure pod spec) duplicate content in the reference files, and the summary templates with X/Y/Z placeholders add bulk that could be tightened. | 4 / 5 |
Actionability | Concrete tool invocations with named parameters ("Run snyk_iac_scan with: path... var_file... scan: 'planned-values'"), executable terraform plan/show commands, complete HCL/YAML fixes, and an error-handling table with specific resolutions. Not 5 because the core scan instructions use unfilled placeholders and pseudocode-style parameter blocks rather than fully specified calls for a concrete case. | 4 / 5 |
Workflow Clarity | A clear five-phase sequence (Discovery → Execute Scan → Analyze → Remediation → Verification) with an explicit re-scan verification loop, before/after improvement reporting, and remaining-issue documentation. The error-handling table provides recovery paths, matching the anchor's "explicit validation steps; feedback loops for error recovery". | 5 / 5 |
Progressive Disclosure | The body is well-sectioned but never mentions the two existing reference files (references/terraform-security-patterns.md, references/kubernetes-security-patterns.md), so the bundle's detailed patterns are undiscoverable from SKILL.md. The inline Phase 4 examples partially duplicate that reference content — "references present but not clearly signaled; content that should be separate is inline" fits better than the 4 anchor, which requires references to be mostly clearly signaled. | 3 / 5 |
Total | 16 / 20 Passed |