Content
85%Weight 40%Scale 1-3Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A lean, well-structured instruction-only skill with clear sequencing, an explicit prove-before-variants checkpoint, and good progressive disclosure through a single one-level reference. Its main weakness is actionability: the analytical procedure is concrete about what to track but provides no worked example or template for the evidence blocks it repeatedly invokes.
Suggestions
Add a minimal worked example or template showing the three 'compact evidence blocks' (malicious chunk / planner drift / final tool args) so the repeatedly-invoked evidence layout is concrete rather than only described.
Include one short end-to-end exploit-chain illustration mapping Quick Start steps 1–4 (untrusted content → model-visible boundary → tool/secret artifact → minimal proof) so the guidance is adaptable to a real challenge.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The ~45-line body is lean and assumes Claude's competence — it never explains what prompt injection is, and each line ('Identify the first untrusted content that becomes model-visible', 'Prefer the smallest transcript that still demonstrates the bug') earns its place, matching the score-3 'lean and efficient' anchor. | 3 / 3 |
Actionability | Quotes 'Record the exact point where text becomes a tool argument, file path, network target, or secret request' and 'Prove one minimal exploit chain before exploring variants' — the guidance is specific about which artifacts to track, but it stays procedural with no worked example or template for the repeatedly-referenced 'compact evidence blocks', fitting the score-2 'concrete guidance but incomplete; missing key details' anchor rather than the copy-paste-ready score-3. | 2 / 3 |
Workflow Clarity | Quotes the numbered Quick Start (steps 1–5) and the three-phase Workflow, with an explicit checkpoint 'Prove one minimal exploit chain before exploring variants' plus a referenced checklist — a clear sequence with an explicit (not implicit) gating checkpoint, matching the score-3 anchor; this is an analysis skill so destructive/batch feedback loops do not cap it. | 3 / 3 |
Progressive Disclosure | Quotes '## Read This Reference — Load `references/prompt-injection.md` for the checklist, evidence layout, and common prompt-boundary pitfalls' — a well-signaled, verified one-level-deep reference with a concise overview body, matching the score-3 'clear overview with well-signaled one-level-deep references' anchor. | 3 / 3 |
Total | 11 / 12 Passed |