Content
77%Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A well-structured, highly actionable security-testing skill with a clear sequenced workflow and concrete standards-backed items. Its main weaknesses are conciseness (inline catalog duplication and time-sensitive version detail) and progressive disclosure (large tables and one full surface's items live in SKILL.md alongside the reference bundle).
Suggestions
Move the full nine-surface ASVS table and Top 10/WSTG table into references/per-surface-test-items.md (or a dedicated reference file), keeping only the classification table and a pointer in SKILL.md to remove the inline duplication.
Relocate the ASVS 5.0.0 release-date and version-migration discussion into a clearly marked 'Version notes' or 'Deprecated/old patterns' section so the time-sensitive material does not penalize the lean overview.
Inline only the Authentication surface as a representative example and defer all nine surfaces' Manual/Automated items to the reference, since the body already states the remaining eight follow the same shape.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Mostly efficient and assumes Claude's intelligence (no OWASP primers), but reproduces the full nine-surface ASVS and Top 10/WSTG tables inline despite a references/per-surface-test-items.md bundle existing, and includes time-sensitive detail (the ASVS 5.0.0 release date) outside any deprecated/old-patterns section — matching the score-2 anchor of mostly efficient with some unnecessary content rather than the lean score-3. | 2 / 3 |
Actionability | Gives concrete, executable guidance: named path/content signals, specific ASVS requirement IDs (2.4.1, 5.3.4, 12.6.1), named WSTG sections, and runnable per-item instructions like 'Fetch another tenant's document id with a valid token' and 'Run static-analysis rules for plaintext or reversibly-stored credentials against the changed files only', plus a copy-paste-ready worked example — matching the score-3 anchor for an instruction-only skill. | 3 / 3 |
Workflow Clarity | Clear four-step sequence (mark surfaces, attach ASVS, tag Top 10/WSTG, emit items) with explicit classification checkpoints ('Path first, content second', 'a surface with zero changed lines is excluded') and a 7-item ordered output format with a mandatory disclaimer, matching the score-3 anchor of a clear sequence with explicit checkpoints. | 3 / 3 |
Progressive Disclosure | Has a well-signaled one-level-deep reference ('Pull the full catalog from references/per-surface-test-items.md', and the file exists), but much catalog content (both standards tables and the full Authentication item set) is duplicated inline rather than split out, matching the score-2 anchor where content that should be separate is inline rather than the cleanly-split score-3. | 2 / 3 |
Total | 10 / 12 Passed |