Content
65%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A rich, well-organized adversary-emulation reference with strong actionability and conciseness, weakened by the absence of validation checkpoints in the offensive workflow and a monolithic single-file structure with no progressive disclosure to supporting references.
Suggestions
Add explicit validation/verification checkpoints to the emulation guidance (e.g. confirm scope/authorization before each phase, verify implant beaconing and detection telemetry after each step) to lift workflow clarity above 3.
Split the TTP-by-tactic catalog and the signature tooling/malware table into separate reference files (e.g. references/ttps.md, references/malware.md) and link them from SKILL.md to improve progressive disclosure.
Trim or collapse redundant ATT&CK sub-technique listings where the parent technique already conveys the behavior, to tighten token efficiency.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Dense, specific reference content that assumes Claude's intelligence (no basic concept padding), though the sheer breadth of the inline TTP and malware catalogs makes it longer than necessary. | 4 / 5 |
Actionability | The emulation and detection sections give concrete, named tools and specific signals (Mimikatz, secretsdump.py, PsExec, Sysmon EID 10, RunAsPPL, ASR rules), with minor gaps in exact command syntax. | 4 / 5 |
Workflow Clarity | Emulation guidance follows a clear kill-chain sequence, but there are no explicit validation/verification checkpoints; per the feedback-loops rule for destructive/offensive operations this caps the score at 3. | 3 / 5 |
Progressive Disclosure | Well-structured with clear section headers, but everything is inlined in a single ~200-line file with no bundle references; the TTP catalog and malware signature table are candidates for separate reference files. | 3 / 5 |
Total | 14 / 20 Passed |