Content
86%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is a tight, well-structured instruction-only methodology that assumes competence and offloads the checklist to a clearly signaled one-level-deep reference. It falls just short of top marks on actionability and workflow clarity because it lacks a worked minimal-exploit example and an explicit error-recovery loop.
Suggestions
Add one compact worked example showing a minimal exploit chain (untrusted chunk -> rewritten planner state -> final tool invocation) so the actionability guidance is fully concrete.
Insert an explicit feedback loop in the Workflow, e.g. 'If the chain does not reproduce a side effect, narrow the transcript and re-prove before exploring variants', to reach the validation/checkpoint anchor.
Link the reference with markdown syntax (references/prompt-injection.md) in addition to the backtick form to make navigation unambiguous.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is lean bullet-and-short-prose guidance with no concept padding (it never explains what prompt injection is) and assumes Claude's domain competence, so every line earns its place per the lean-and-efficient anchor. | 5 / 5 |
Actionability | Directives like 'Identify the first untrusted content that becomes model-visible', 'Record the exact point where text becomes a tool argument, file path, network target, or secret request', and 'Prove one minimal exploit chain before exploring variants' are concrete and actionable, but no worked transcript example illustrates a minimal chain, leaving a minor gap versus the fully-concrete 5 anchor. | 4 / 5 |
Workflow Clarity | A numbered Quick Start (1-5) and a three-phase Workflow give a clear sequence with a proof checkpoint ('Prove one minimal exploit chain before exploring variants') and a side-effect check ('Separate instruction drift from actual side effect'), but there is no explicit error-recovery feedback loop for when a chain fails to reproduce, which is the missing checkpoint versus the 5 anchor. | 4 / 5 |
Progressive Disclosure | The body is a concise overview and points to a single one-level-deep reference via a dedicated 'Read This Reference' section that states its contents ('checklist, evidence layout, and common prompt-boundary pitfalls'); the reference file does not nest further, matching the clear-overview-with-well-signaled-one-level-deep-references anchor. | 5 / 5 |
Total | 18 / 20 Passed |