Content
71%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
Highly actionable and well-sequenced, with excellent executable examples throughout. The weaknesses are a monolithic ~490-line structure with no reference files, and notable redundancy (the cookie-theft payload family repeated four times) plus prerequisite sections that restate knowledge Claude already has.
Suggestions
Move the payload catalogs (Phase 6 filter/encoding bypasses, the Common XSS Payloads table, and the four worked examples) into reference files such as references/payloads.md and references/examples.md, keeping SKILL.md to the workflow overview and detection checklist.
Collapse the four near-duplicate cookie/session-capture payloads (Phase 2, Cookie Theft Payload, Session Hijacking Template, Example 1) into a single canonical exfiltration snippet referenced once.
Trim the 'Inputs/Prerequisites' and 'Technical Requirements' sections to the authorization/scope items that actually gate the work, dropping generic knowledge statements like 'Understanding of JavaScript execution in browser context', and add an explicit post-test cleanup step (removing stored test payloads and captured data) to the core workflow.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Much of the body is dense, copy-paste reference material (payload tables, sinks/sources lists) rather than prose padding, but there is real fat: the cookie/session-capture payload appears in essentially the same form four times (Phase 2, 'Cookie Theft Payload', 'Session Hijacking Template', Example 1), and the 'Technical Requirements'/'Inputs' sections restate knowledge Claude already has ('Understanding of JavaScript execution in browser context'). Not 2 because the bulk is reference content, not explanatory filler, but it could be cut substantially. | 3 / 5 |
Actionability | Fully executable throughout: concrete payloads ('<img src=x onerror=alert(1)>'), raw HTTP examples ('POST /api/comments ... {"body": "<script>alert('XSS')</script>"}'), a context-to-payload table, working CSP-bypass JSONP snippets, and a troubleshooting table mapping failure symptoms to specific fixes. Copy-paste ready and covering the common cases. | 5 / 5 |
Workflow Clarity | The six-phase sequence (detect → classify XSS type → stored → reflected → DOM → HTMLi → bypass) is clear, with observation checkpoints ('Monitor for: Raw HTML reflection without encoding...') and a detection checklist in the Quick Reference. Not 5 because there is no explicit validate-and-cleanup step after injecting into shared targets (e.g., removing stored test payloads), which the guardrails gesture at ('Limit cookie/session capture to demonstration purposes') but never sequence as a step. | 4 / 5 |
Progressive Disclosure | Section headers and tables give reasonable structure, but the ~490-line body is monolithic: the payload catalogs (Phase 6 filter bypasses, Common XSS Payloads table), the four full examples, and the troubleshooting matrix all belong in separate reference files, and no bundle files exist. This matches the 3 anchor — 'some structure... content that should be separate is inline' — rather than 2, since structure is present, not minimal. | 3 / 5 |
Total | 15 / 20 Passed |