Content
57%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is a well-structured overview with exemplary progressive disclosure to a real, single reference file. Its weaknesses are redundancy across the Check/Fix/Explain/Code Review modes, missing executable header values in the body, and no explicit recovery loop when verification fails.
Suggestions
Inline the two header values (e.g. `Cross-Origin-Opener-Policy: same-origin` + `Cross-Origin-Embedder-Policy: require-corp`) so the body's core action is executable without opening the reference.
Add an explicit ordered workflow with a feedback loop, e.g. "3. Verify `self.crossOriginIsolated === true`; if false, re-check network responses for missing CORP/CORS headers on cross-origin subresources and retry".
Consolidate the repeated audit/verify guidance spread across Quick Reference, Check, Fix, and Code Review into one sequence to cut duplicated tokens.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The ~30-line body is short, but it repeats itself: the audit-then-verify guidance appears in Quick Reference ("Audit every cross-origin script, iframe... before enforcing COEP"), Fix ("Add COOP and COEP only after auditing dependencies"), and Code Review ("Flag exact responses or integrations that would block isolation"), and the intro paragraph explains COOP/COEP purpose Claude already knows ("Cross-origin isolation reduces opener-based attacks and XS-Leak risk"). It could be tightened into a single ordered procedure. | 3 / 5 |
Actionability | There is one fully concrete check ("Verify `self.crossOriginIsolated === true`"), but the body gives no executable header values — "Add COOP and COEP" without specifying `Cross-Origin-Opener-Policy: same-origin` / `Cross-Origin-Embedder-Policy: require-corp` — and defers all code to the reference file, leaving key details missing from the body itself. | 3 / 5 |
Workflow Clarity | A sensible sequence is implied across sections (audit dependencies → enforce COOP/COEP → ensure CORP/CORS on subresources → verify crossOriginIsolated), and a verification checkpoint is stated twice. But it is never laid out as an explicit ordered procedure, and there is no recovery guidance for the common failure case where verification fails because one resource blocks isolation. | 3 / 5 |
Progressive Disclosure | The body is a clean overview with well-organized sections and a single clearly signaled, one-level-deep pointer — "For full implementation details, code examples, and framework-specific guidance, see `references/rule.md`" — and that file exists in the bundle with the expected content. | 5 / 5 |
Total | 14 / 20 Passed |