Content
71%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is a well-structured, appropriately split overview for a simple single-purpose skill: concrete policy values, a clear check/fix/review flow, and a clean one-level pointer to the detailed reference file. Its main flaws are repetition of the leak rationale across three sections and a Check step that lacks a concrete verification command.
Suggestions
State the sensitive-URL leak risk once (the intro example already covers it) and cut the duplicate Quick Reference bullet and Check-section restatement.
Add a concrete verification command to the Check section, e.g., `curl -sI https://example.com | grep -i referrer-policy`, so detection is executable rather than descriptive.
Merge the Fix section's repeated recommendation ("Add Referrer-Policy: strict-origin-when-cross-origin") with the Quick Reference to remove the duplicated value statement.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is short and mostly lean, but the sensitive-URL-leak point appears three times (intro paragraph, Quick Reference bullet "Sensitive URLs (reset tokens, private IDs) in query strings can be exposed", and the Check section), and the recommended value is stated twice. It could be tightened without losing anything. | 3 / 5 |
Actionability | Concrete, copy-paste-ready guidance dominates: "Use Referrer-Policy: strict-origin-when-cross-origin", "Never use unsafe-url", and "consider no-referrer or same-origin" for sensitive pages. The minor gap is the Check section, which says to verify the header without giving a command (e.g., curl -I) to do so. | 4 / 5 |
Workflow Clarity | The Check → Fix → Explain → Code Review sections form a coherent sequence, and Code Review includes an explicit verification step ("verify them against the effective production-like response"). No feedback loop (what to do when the check finds a bad value mid-review) is spelled out, keeping it just below the top anchor. | 4 / 5 |
Progressive Disclosure | The body is a genuine overview (~45 lines) with full implementation details, code examples, and framework-specific guidance clearly signaled in one reference, references/rule.md, which exists and is exactly one level deep. Content split and navigation match the top anchor. | 5 / 5 |
Total | 16 / 20 Passed |