Content
71%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is a well-structured overview with excellent progressive disclosure into a real, one-level reference file, and its Check/Fix guidance is concrete. The main costs are a redundant concept explanation in the intro and an unsurfaced hash-generation command and verification step.
Suggestions
Cut the intro's explanation of what SRI is and why it matters (Claude already knows this), and drop the fourth Quick Reference bullet that repeats it verbatim in substance.
Surface the one-line openssl hash command (or an explicit pointer to the Generating Hash Values section) in the Fix section so the core executable step is in the body.
Add a brief verify step after Fix (re-check the rendered markup / confirm the hash matches) or link the Verification section from the body.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is mostly lean, but the 3-sentence intro paragraph explains what SRI is and why it matters — a concept Claude already knows — and the Quick Reference bullet 'SRI blocks execution if the file hash doesn't match, preventing CDN compromise attacks' repeats the intro. It fits anchor 3 ('some unnecessary explanation or could be tightened') better than anchor 4, since the concept explanation is more than a minor instance. | 3 / 5 |
Actionability | Concrete guidance includes exact attribute syntax ('integrity="sha384-..."', 'crossorigin="anonymous"'), specific tag types ('<script> and <link rel=stylesheet> tags ... that load from CDNs'), and a precise Check instruction. Not anchor 5 because the key executable step — the hash-generation command — is only gestured at ('Generate hashes with openssl or online tools') and deferred to the reference without being surfaced. | 4 / 5 |
Workflow Clarity | The Check → Fix sequence is clear and the Check/Fix/Explain/Code Review modes are unambiguously delineated for this single-purpose review skill. Not anchor 5 because post-fix verification (confirm the hash matches and the page still loads) is not surfaced in the body even though a Verification section exists in references/rule.md; not anchor 3 since the sequence and task boundaries are fully explicit. | 4 / 5 |
Progressive Disclosure | The ~45-line body is a well-organized overview (Quick Reference, Check, Fix, Explain, Code Review) with a clearly signaled one-level-deep pointer — 'For full implementation details, code examples, and framework-specific guidance, see references/rule.md' — and the referenced file exists and holds those details without nested references. | 5 / 5 |
Total | 16 / 20 Passed |