Content
65%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is maximally token-efficient and information-dense, but it reads as a personal shorthand cheat sheet rather than skill guidance: commands are truncated fragments instead of executable invocations, and there is no sequencing or validation guidance for inherently destructive multi-step attacks. Structure is a single unsectioned block despite covering roughly ten distinct attack areas.
Suggestions
Break the single code block into short sections (recon, ADCS, NTLM relay/coerce, Kerberos, CVEs, Linux internal) so each attack area is navigable instead of one wall of text.
Expand the truncated commands into complete invocations (e.g. full `certipy find -u user@domain -dc-ip <ip> -vulnerable` and a well-formed `ntlmrelayx -t ldap://dc --escalate-user`), since the current shorthand is not executable as written.
Add brief validation checkpoints for the destructive paths (e.g. how to confirm a relay/ESC1 succeeded before moving to DCSync, and how to verify Zerologon exploitation before dumping), which would also lift the workflow-clarity cap.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is a single dense cheat-sheet block ("🚨ADCS(Certipy一把梭): certipy find -vulnerable", "secretsdump -just-dc → krbtgt hash→Golden Ticket") with zero padding, no explanation of concepts Claude already knows, and every token carrying technique information. This matches the lean/efficient anchor exactly. | 5 / 5 |
Actionability | Real tools and command fragments are present ("certipy find -vulnerable", "ntlmrelayx -t ldap--escalate-user", "GetNPUsers/GetUserSPNs"), but they are compressed shorthand with missing flags, targets, and context — e.g. "-t ldap--escalate-user" is malformed — so nothing is copy-paste executable. This is the "some concrete guidance but incomplete, missing key details" anchor, not 4's mostly-executable level. | 3 / 5 |
Workflow Clarity | A rough attack flow is discernible (侦察 recon → credential attacks → relay/coerce chains → DAcl/DCSync → Golden Ticket) with priority markers ("🚨一击致命域CVE(先测,命中直接域管)"), but there is no explicit step sequence and no validation checkpoints or feedback loops anywhere. These are destructive operations, which caps this dimension at 3 even though a sequence is implied. | 3 / 5 |
Progressive Disclosure | No bundle files exist and at ~15 lines the skill does not need external references, so the small-skill exception could apply — but the body is one monolithic code block under a single header with no internal sections or navigation, matching "some structure but could be better organized" rather than the well-organized-sections bar for 4-5. | 3 / 5 |
Total | 14 / 20 Passed |