CtrlK
BlogDocsLog inGet started
Tessl Logo

active-directory-attack

内网域攻击:BloodHound,Kerberoast,ADCS ESC1/ESC8,NTLM Relay,Coerce,DACL,DCSync,Zerologon/NoPac/PrintNightmare,mitm6,LLMNR,Linux内网。Use when attacking Active Directory, ADCS, NTLM relay, or internal domain.

64

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/active-directory-attack/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

65%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a token-efficient reference cheatsheet that avoids padding, but it is a monolithic code block of abbreviated command fragments with no sequenced workflow or validation checkpoints. Restructuring into organized sections with complete commands would lift actionability and workflow clarity.

Suggestions

Replace the single code block with organized markdown sections (one per attack category) so the overview is navigable instead of a monolithic wall of text.

Expand abbreviated entries into complete, copy-paste-ready commands (e.g., full certipy/ntlmrelayx/secretsdump invocations with required flags and target placeholders) to raise actionability.

For destructive/batch operations (DCSync, NTLM relay, Zerologon), add a short sequenced workflow with validation checkpoints (e.g., verify privileges before exploiting, confirm success after) to satisfy workflow clarity.

DimensionReasoningScore

Conciseness

The body is a dense, compressed cheatsheet inside one code block that adds only domain-specific knowledge (tool names, CVEs, attack chains) and never explains concepts Claude already knows, matching the lean and efficient level-3 anchor.

3 / 3

Actionability

Real command fragments appear ("certipy find -vulnerable", "ntlmrelayx -t ldap --escalate-user", "secretsdump -just-dc", "CONFIG SET dir") but many entries are abbreviated technique descriptions ("ESC1指定SAN申域管证书") rather than complete, copy-paste-ready commands, so key details are missing — the level-2 anchor.

2 / 3

Workflow Clarity

Attack chains are implied via arrows ("PetitPotam...→喂给relay", "mitm6劫持...→WPAD→ntlmrelayx到LDAP/ADCS") but there is no numbered sequenced procedure, and destructive/batch operations lack any validation or verification checkpoints, which caps workflow clarity at 2.

2 / 3

Progressive Disclosure

Although the skill is short with no external references, it is presented as a single monolithic code block under one heading rather than well-organized markdown sections, so it sits at the level-2 'some structure but could be better organized' anchor rather than the well-organized level-3.

2 / 3

Total

9

/

12

Passed

Description

90%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A tightly written, highly specific description with an explicit Use-when trigger clause and clear niche separation. Its only weakness is specificity framing: it is a keyword/topic dump rather than a list of concrete action verbs.

DimensionReasoningScore

Specificity

The description enumerates many concrete techniques ("BloodHound,Kerberoast,ADCS ESC1/ESC8,NTLM Relay,Coerce,DACL,DCSync,Zerologon/NoPac/PrintNightmare,mitm6,LLMNR") but as a noun/keyword list with no action verbs, so it names the domain richly without describing concrete actions; not a level 3 action list like 'Extract... fill... merge'.

2 / 3

Completeness

It states what the skill covers (the enumerated AD attack techniques) and provides an explicit when-trigger clause ("Use when attacking Active Directory, ADCS, NTLM relay, or internal domain"), satisfying both halves; the presence of the Use-when clause avoids the cap at 2.

3 / 3

Trigger Term Quality

"Use when attacking Active Directory, ADCS, NTLM relay, or internal domain" plus the leading "内网域攻击" give good coverage of natural terms a red-team user would actually say, matching the level-3 anchor for natural keyword coverage.

3 / 3

Distinctiveness Conflict Risk

The niche is highly specific (internal-domain AD/ADCS/NTLM-relay attacks) with distinct triggers, making it unlikely to conflict with or trigger for unrelated skills.

3 / 3

Total

11

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
Ed1s0nZ/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.