Content
85%Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A highly actionable, well-sequenced operational skill with concrete commands, a mandatory triage feedback loop, and clean sectioning. The main drag is token efficiency from repeated passive/active warnings and recurring 'Per [zap-base]' citations that could be tightened.
Suggestions
State the passive-only-vs-active distinction once (e.g. in Overview or Step 5) and reference it from Anti-patterns/Limitations instead of repeating it four times.
Cite the zap-base reference once near the top rather than repeating 'Per [zap-base][zap-base]' before nearly every section.
Condense or paraphrase the verbatim documentation quote in the Overview to the operationally relevant fact (default 1-minute spider then passive scan) to save tokens.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Mostly efficient (command- and table-heavy), but repeats the passive-vs-active warning in Overview, Step 5, Anti-patterns, and Limitations, and cites 'Per [zap-base][zap-base]' ~6 times; the verbatim doc quote could be trimmed. | 2 / 3 |
Actionability | Provides copy-paste-ready executable docker commands, a real GitHub Actions YAML, and a concrete zap-config.tsv with a mandatory justification template — fully actionable, not pseudocode. | 3 / 3 |
Workflow Clarity | Steps 1-8 are clearly sequenced (install → scan → flags → auth → active → triage → output → CI), with a MANDATORY triage feedback loop (justification template + Re-review-date + quarterly audit) and checklists (anti-patterns table). | 3 / 3 |
Progressive Disclosure | No bundle files exist; the body is well-organized into clearly headed sections with a one-level References list (external docs + sister skills) and no nested reference chains, so navigation is easy. | 3 / 3 |
Total | 11 / 12 Passed |