Content
57%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The skill body is a well-structured, appropriately split overview with excellent progressive disclosure, but the inline guidance stops just short of executable: no header-inspection command, no complete example header, and implicit verification. Trimming the duplicated XSS rationale and the 'Explain' section would tighten token efficiency.
Suggestions
Add one concrete inspection command to the Check section (e.g., 'curl -sI https://example.com | grep -i permissions-policy') so the check step is executable rather than descriptive.
Include a single complete recommended header (e.g., 'Permissions-Policy: camera=(), microphone=(), geolocation=(), payment=(), usb=()') in the Fix section as a copy-paste starting point.
Remove the duplicated XSS/blast-radius bullet (it restates the intro) and fold the 'Explain' section into the intro to save tokens.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is short and mostly efficient (Quick Reference bullets carry real information), but the XSS/blast-radius rationale is stated twice ('A site compromised by XSS... can silently record the user' in the intro and 'Restricting unused features limits the blast radius if your site is compromised by XSS' as a bullet), and the 'Explain' section mostly instructs Claude to do something it already knows how to do. This matches 'Mostly efficient but includes some unnecessary explanation or could be tightened'; not a 4 because the duplication and the filler 'Explain' section are trimmable. | 3 / 5 |
Actionability | There is concrete syntax ('Permissions-Policy: camera=(), microphone=(), geolocation=()' and 'Start with camera=(), microphone=(), geolocation=()'), but the Check section gives no command for actually inspecting headers (e.g., curl -I), and no complete example header or framework config appears inline — details are deferred to references/rule.md. This matches 'Some concrete guidance but incomplete... missing key details'; not a 4 because a ready-to-use header line or inspection command is the obvious missing piece. | 3 / 5 |
Workflow Clarity | The Check → Fix → Explain → Code Review sections form a coherent rough sequence, and 'Code Review' gestures at verification ('verify them against the effective production-like response'), but there is no explicit checkpoint such as how to fetch the live response or how to confirm the header is present after the fix. This matches 'Steps listed but validation gaps; sequence present but checkpoints missing or implicit'; not a 4 because the verification step is implicit rather than an actionable command. | 3 / 5 |
Progressive Disclosure | The body is a concise overview and the 166-line detail file is split out behind a clearly signaled, one-level-deep reference ('For full implementation details, code examples, and framework-specific guidance, see references/rule.md'), and references/rule.md exists in the bundle with no further nesting. This matches the anchor 'Clear overview with well-signaled one-level-deep references; content appropriately split; easy navigation'. | 5 / 5 |
Total | 14 / 20 Passed |