Content
60%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
Highly actionable — abundant executable payloads, commands, and a working fuzz script — organized into a coherent ten-phase sequence with manual-verification mentions. But it is a padded ~490-line monolith that re-teaches basic HTML and inlines everything, wasting context window and ignoring progressive disclosure entirely.
Suggestions
Split the payload catalogs (Phase 3 basic tags, Phase 8 bypass/encoding variants, quick-reference tables) into references/payloads.md and reference them from a lean SKILL.md overview.
Delete knowledge Claude already has: the Phase 1 definition of injection, the basic <b>/<i>/<u>/<font> tag list, and the encoding table explaining that %3C is '<'.
Turn verification into explicit checkpoints per phase (e.g. after each payload class: confirm rendering in browser, record reflected vs stored behavior, then proceed) instead of one-line mentions.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The ~490-line body pads several sections with knowledge Claude already has: an explanation of what HTML injection is, trivial tags like '<b>Bold Text</b>', '<i>Italic Text</i>', '<u>Underlined Text</u>' in Phase 3, and an encoding table explaining that '%3C' means '<'. It is not 1 because the bulk is genuinely skill-specific payload material, not library-tutorial filler; it is not 3 because the unnecessary sections are numerous, not occasional. | 2 / 5 |
Actionability | Concrete payloads throughout, copy-paste curl tests ('curl -s "http://target.com/search?q=<b>Bold</b>" | grep -i "bold"'), a runnable Python fuzzing script with imports and error handling, numbered Burp/ZAP procedures, and ready-made phishing/defacement HTML. It is not 4 because the examples cover the common cases end-to-end and the code is executable as written. | 5 / 5 |
Workflow Clarity | The ten phases form a logical sequence (understand → map injection points → basic testing → injection types → exploit construction → bypass → automation → remediation), with verification steps like 'Check if HTML renders in response', 'Manually verify successful injections', and 'Validate findings manually'. It is not 5 because verification is mentioned rather than built in as explicit checkpoints or feedback loops (e.g. no verify-and-retry cycle per payload class); it is not 3 because the troubleshooting table does provide a rendered-failure → alternate-encoding recovery path. | 4 / 5 |
Progressive Disclosure | The entire skill is a single ~490-line monolithic file with zero references to bundle files; large payload catalogs (Phase 3/8 payloads, encoding tables, quick-reference tables) clearly belong in references/ files per the rubric's overview-then-detail model. It is not 1 because the file is well-structured with clear headers and an internal quick-reference section, so navigation is possible; it is not 3 because there are no references at all and roughly double the inline content of the anchor-3 example. | 2 / 5 |
Total | 13 / 20 Passed |