Content
88%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
An exceptionally lean, contract-driven routing skill: no token waste, explicit validation and failure-recovery steps for destructive/live operations, and a clean one-level-deep reference structure with conditional loading triggers. The only flaws are minor: a few sections stop at policy without showing the concrete command, and merge-queue.md is orphaned from the navigation.
Suggestions
Link merge-queue.md where the body mentions "merge queues" (the require-pull-requests clause) so the existing reference file is discoverable.
Give one concrete readback example (e.g. the `gh api` call for a changed setting or Environment) so the read-back requirement is executable, not just stated.
Anchor abstract invariants like "Make GitHub the enforceable shell around the repository's existing... contracts" to a concrete first action so the entry point is as actionable as the routes that follow.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is dense operational directive with zero padding — e.g. "Pull requests execute untrusted code with read-only credentials", "Publish one immutable payload and deploy that payload instead of rebuilding it" — and never explains concepts Claude already knows (what Actions or Dependabot are). Every line states a contract or a routing rule, matching anchor 5's "every token earns its place". | 5 / 5 |
Actionability | Routing is concrete and conditional ("Read [Actions security](references/actions-security.md) when adding workflows or changing code execution... credential, publication, signing, or deploy boundaries") and exact tooling is named ("Run repository gates plus `actionlint` and `zizmor`"). It stops short of anchor 5 because most sections give policy and decision rules rather than copy-paste commands — e.g. the readback requirement never shows the `gh api` call that would satisfy it. | 4 / 5 |
Workflow Clarity | A clear sequence runs route selection ("Select the relevant route below before loading references") through shared contracts, route-specific work, and "Verify and Finish", with explicit validation checkpoints ("Run repository gates plus `actionlint` and `zizmor` when workflows changed") and error-recovery feedback loops for risky live operations ("On partial failure, reconcile durable state before retry; never create a new version... merely to make a workflow green", plus recording before-state and rollback path before authorized mutations). The structured Output block closes the process as a checklist. | 5 / 5 |
Progressive Disclosure | The body is a pure overview routing to 16 one-level-deep references, every link well-signaled with a conditional trigger ("only when that tool is selected", "only after a concrete failure"), and all 15 linked paths resolve to real files in references/. It misses anchor 5 on one real navigation gap: references/merge-queue.md exists but is never linked from the body (the text mentions "merge queues" without pointing to it), leaving that content undiscoverable. | 4 / 5 |
Total | 18 / 20 Passed |