Content
92%Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A tight, highly actionable skill body with a clear validated methodology; its only structural gap is that the existing reference bundle files (IOC and CVE-to-APT mappings) are not linked from the SKILL.md overview. Signaling those references would complete the progressive-disclosure picture.
Suggestions
Add a '## References' section linking references/anyrun-free-iocs.md and references/cve-apt-mapping.md so the available bundle material is discoverable from the overview.
Optionally move the 22-row actor catalog into a references file and keep a condensed pointer in SKILL.md, since the catalog is reference data rather than methodology.
Make the scope-validation step an explicit validate→fix→retry loop (e.g. 'if a planned TTP is out of RoE, down-scope and re-confirm before proceeding') to strengthen the error-recovery feedback path.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Lean and information-dense — a tight emulation/pentest distinction, a RoE warning, a 5-step methodology, and a catalog of attributed actors — with no padding of generic concepts Claude already knows, so it earns 3 rather than 'mostly efficient but could be tightened' (2). | 3 / 3 |
Actionability | Gives concrete, copy-ready guidance — `load_skill <slug>` with a worked example, `ask_user_question`, the explicit kill-chain sequence to walk, and 'cite the ATT&CK ID' — which is actionable instruction rather than vague direction or pseudocode (2). | 3 / 3 |
Workflow Clarity | A clear 5-step sequence (Select → Load → Scope → Emulate → Measure) with explicit validation gates in the destructive context — step 3's scope intersection, tool-call-time out-of-scope checks, and canary substitution for wipers — so validation is present, not missing (which would cap it at 2). | 3 / 3 |
Progressive Disclosure | The body is well-organized as an overview, but the two bundle files present in references/ (anyrun-free-iocs.md, cve-apt-mapping.md) are never referenced or signaled from SKILL.md, matching the anchor 'references present but not clearly signaled' rather than the well-signaled one-level-deep ideal (3). | 2 / 3 |
Total | 11 / 12 Passed |