Content
78%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is a well-structured, token-efficient overview that defers implementation detail appropriately to a single verified one-level-deep reference, with concrete check/fix guidance and a coherent workflow. Its only weaknesses are minor: a duplicated CSP bullet in Quick Reference and an implicit rather than explicit verification feedback loop.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The ~46-line body is lean and sectioned with no padding explaining concepts Claude already knows, but Quick Reference contains two bullets both stating that 'upgrade-insecure-requests' is the practical fix, and the opening line duplicates the 'Why It Matters' framing from the reference. These are minor instances of over-explanation that could be trimmed, matching anchor 4 rather than the fully lean anchor 5. | 4 / 5 |
Actionability | The Check and Fix sections give concrete, specific instructions — exact attributes to scan ('Check <script src>, <img src>, <link href>, <iframe src>, and CSS url() values for http:// URLs') and the exact remediation ('Replace all http:// resource URLs with https:// equivalents', 'Add Content-Security-Policy: upgrade-insecure-requests'). No executable command appears inline in SKILL.md itself (the grep and config snippets live in references/rule.md), leaving minor gaps that fit anchor 4. | 4 / 5 |
Workflow Clarity | The Check → Fix → Explain → Code Review sections form a clear, coherent sequence, and a verification checkpoint is present ('verify them against the effective production-like response'). However, verification is a single implicit step with no explicit validate→fix→retry feedback loop, matching 'clear sequence with most checkpoints present; minor validation gaps' rather than anchor 5. | 4 / 5 |
Progressive Disclosure | The body is a concise, well-sectioned overview with one clearly signaled, one-level-deep reference — 'For full implementation details, code examples, and framework-specific guidance, see references/rule.md' — and that file exists and delivers exactly what the pointer promises (code examples, CSP configs for Nginx/Next.js, detection tooling) with no nested references. This matches 'clear overview with well-signaled one-level-deep references; easy navigation'. | 5 / 5 |
Total | 17 / 20 Passed |