Content
71%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is a well-structured overview with genuinely actionable check/fix/review guidance and exemplary progressive disclosure to a real, one-level-deep reference file. Its main weakness is mild redundancy and a textbook SOP explainer that adds tokens without adding information Claude doesn't already have.
Suggestions
Cut or compress the opening paragraph explaining what the Same-Origin Policy is — Claude already knows this — and keep at most the one-line consequence framing.
Deduplicate the overlapping review instructions between the Fix and Code Review sections (e.g. the CORS-permissiveness review appears in both) so each section earns its place.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The opening paragraph explains the Same-Origin Policy — a concept Claude already knows — and the Check, Fix, and Code Review sections repeat overlapping instructions ("review CORS configuration" appears in both Fix and Code Review). Mostly efficient but includes unnecessary explanation and could be tightened, matching anchor 3. | 3 / 5 |
Actionability | Concrete, directive guidance throughout: "Always verify event.origin before processing postMessage data", "Never set Access-Control-Allow-Origin: * for authenticated endpoints", "Reject unvalidated redirect targets such as next, redirect, or callbackUrl", and "Check login, logout, SSO, and return-to flows for open redirects". Instruction-only but actionable; not a 5 because no example of a violation or its fix appears inline — everything concrete of that kind is deferred to the reference file. | 4 / 5 |
Workflow Clarity | The Check → Fix → Explain → Code Review sequence is a coherent, ordered workflow with verification woven in ("state how the change should be verified in the browser"). Not a 5 because the body itself contains no explicit validate-and-report checkpoint (verification steps live in references/rule.md), leaving a minor validation gap. | 4 / 5 |
Progressive Disclosure | The body is a compact, well-sectioned overview that defers all implementation detail through a clearly signaled one-level-deep pointer ("For full implementation details, code examples, and framework-specific guidance, see references/rule.md"), and that file exists and contains exactly that content. No inlining of material that belongs in the reference. | 5 / 5 |
Total | 16 / 20 Passed |