CtrlK
BlogDocsLog inGet started
Tessl Logo

active-directory-attack

内网域攻击:BloodHound,Kerberoast,ADCS ESC1/ESC8,NTLM Relay,Coerce,DACL,DCSync,Zerologon/NoPac/PrintNightmare,mitm6,LLMNR,Linux内网。Use when attacking Active Directory, ADCS, NTLM relay, or internal domain.

60

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/active-directory-attack/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is maximally token-efficient and information-dense, but it reads as a personal shorthand cheat sheet rather than skill guidance: commands are truncated fragments instead of executable invocations, and there is no sequencing or validation guidance for inherently destructive multi-step attacks. Structure is a single unsectioned block despite covering roughly ten distinct attack areas.

Suggestions

Break the single code block into short sections (recon, ADCS, NTLM relay/coerce, Kerberos, CVEs, Linux internal) so each attack area is navigable instead of one wall of text.

Expand the truncated commands into complete invocations (e.g. full `certipy find -u user@domain -dc-ip <ip> -vulnerable` and a well-formed `ntlmrelayx -t ldap://dc --escalate-user`), since the current shorthand is not executable as written.

Add brief validation checkpoints for the destructive paths (e.g. how to confirm a relay/ESC1 succeeded before moving to DCSync, and how to verify Zerologon exploitation before dumping), which would also lift the workflow-clarity cap.

DimensionReasoningScore

Conciseness

The body is a single dense cheat-sheet block ("🚨ADCS(Certipy一把梭): certipy find -vulnerable", "secretsdump -just-dc → krbtgt hash→Golden Ticket") with zero padding, no explanation of concepts Claude already knows, and every token carrying technique information. This matches the lean/efficient anchor exactly.

5 / 5

Actionability

Real tools and command fragments are present ("certipy find -vulnerable", "ntlmrelayx -t ldap--escalate-user", "GetNPUsers/GetUserSPNs"), but they are compressed shorthand with missing flags, targets, and context — e.g. "-t ldap--escalate-user" is malformed — so nothing is copy-paste executable. This is the "some concrete guidance but incomplete, missing key details" anchor, not 4's mostly-executable level.

3 / 5

Workflow Clarity

A rough attack flow is discernible (侦察 recon → credential attacks → relay/coerce chains → DAcl/DCSync → Golden Ticket) with priority markers ("🚨一击致命域CVE(先测,命中直接域管)"), but there is no explicit step sequence and no validation checkpoints or feedback loops anywhere. These are destructive operations, which caps this dimension at 3 even though a sequence is implied.

3 / 5

Progressive Disclosure

No bundle files exist and at ~15 lines the skill does not need external references, so the small-skill exception could apply — but the body is one monolithic code block under a single header with no internal sections or navigation, matching "some structure but could be better organized" rather than the well-organized-sections bar for 4-5.

3 / 5

Total

14

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it names a highly specific niche, enumerates comprehensive concrete technique keywords, and includes an explicit bilingual "Use when..." trigger clause. Its main weakness is that the capability half is a verb-less keyword cloud rather than a statement of what the skill does.

DimensionReasoningScore

Specificity

Names many concrete techniques ("BloodHound", "Kerberoast", "ADCS ESC1/ESC8", "NTLM Relay", "DCSync", "Zerologon/NoPac/PrintNightmare", "mitm6", "LLMNR") with broad coverage. It falls short of 5 because it is a keyword enumeration with no action verbs stating what the skill does, and short of neither 3 since coverage goes well beyond 1-2 actions.

4 / 5

Completeness

Both halves are present: the "what" is the technique/domain list ("内网域攻击:BloodHound,Kerberoast,ADCS ESC1/ESC8...") and the "when" is explicit ("Use when attacking Active Directory, ADCS, NTLM relay, or internal domain"). Not 5 because the "what" is a bare topic list with no verbs — what the skill actually does is left implied; not 3 because the "when" clause is explicit and concrete.

4 / 5

Trigger Term Quality

The trigger clause "Use when attacking Active Directory, ADCS, NTLM relay, or internal domain" contains natural user phrasing, and the keyword list adds many technique names. Missing common variations like "AD", "domain controller", "域控", or "pentest" keeps it below the comprehensive synonym coverage of 5, but it is clearly above the 3 anchor's partial coverage.

4 / 5

Distinctiveness Conflict Risk

"内网域攻击" with specific technique triggers (ADCS ESC1/ESC8, Zerologon, NTLM Relay, mitm6, LLMNR) carves out a clear niche with distinct triggers and minimal risk of firing for the wrong skill.

5 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
AIPentest/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.