Content
76%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
An impressively lean, dense operational checklist with genuinely concrete commands, tool flags, and a sensible passive-to-active escalation doctrine. The main weaknesses are structural: everything lives in one compressed code block rather than organized markdown sections, and the destructive anti-forensics steps (log deletion, timestamp tampering) lack validation checkpoints.
Suggestions
Add explicit validation checkpoints to the destructive/batch guidance: e.g., before selective log deletion, verify your own entries exist and confirm an untouched reference entry count; after timestamp tampering with 'touch -r', verify mtime matches with 'stat'. This would lift workflow_clarity above the destructive-ops cap of 3.
Break the single code block into markdown sections (one heading per discipline: 速率与时序, 流量混淆, 最小足迹, 反取证, 渐进暴露), keeping the compressed checklist lines inside each — this preserves token efficiency while making navigation effortless and would raise progressive_disclosure to 5 under the simple-skill exception.
Expand the few compressed hints into complete one-line commands, e.g. '工具用完即删' → '工具用完即删: shred/内存盘(/dev/shm)写盘的先 srm 再删', moving actionability from mostly-executable to copy-paste ready.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is an extremely lean tactical checklist with zero padding and no explanation of concepts Claude already knows — '核心: 打得进 ≠ 打得稳。被发现即行动归零' is pure signal, and every line adds non-obvious operational detail. Every token earns its place, matching the lean/efficient anchor. | 5 / 5 |
Actionability | Concrete commands and flags appear throughout ('nuclei -rl', 'nmap -T2 --max-rate', 'ffuf -p延迟', X-Forwarded-For/X-Real-IP/CF-Connecting-IP header names, 'unset HISTFILE', 'touch -r', '/dev/shm', DDexec/memfd), plus a concrete XFF verification procedure. Not fully copy-paste ready (5) because several items are compressed hints ('工具用完即删', '别动监控/审计服务') without complete commands. | 4 / 5 |
Workflow Clarity | The '渐进暴露' line provides a sequenced escalation (passive recon → confirm no monitoring → active scan → exploitation) and the XFF bypass includes a verify loop, but destructive and batch operations (selective log deletion, timestamp tampering, automated batch exploitation) lack explicit validation checkpoints. Per the destructive-operations guideline, missing validation caps workflow clarity at 3. | 3 / 5 |
Progressive Disclosure | The skill is self-contained, under 50 lines, with no external bundle files needed; labeled topic lines (速率与时序, 流量混淆, 最小足迹, 反取证) partition the material well. It falls short of 5 because those section labels are buried inside a single code block rather than surfaced as clear markdown sections, making navigation slightly less easy than the well-organized anchor. | 4 / 5 |
Total | 16 / 20 Passed |