Content
50%Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is a thorough, well-structured adversary-emulation reference with specific tool mappings and built-in detection/verification guidance, but it is verbose with restated background, lacks executable commands, and keeps all reference-grade content inline in a single file.
Suggestions
Trim encyclopedic background (attribution consensus, sector lists, dated campaign histories) that Claude already knows, or move it to a references file, to improve conciseness.
Add concrete, executable command snippets or parameters for the highest-value plays (e.g. a Golden SAML / OAuth-consent workflow) instead of only naming the skill to call.
Split the campaign histories, full tooling catalog, and TTP-by-tactic listing into one-level-deep reference files linked from a concise overview to improve progressive disclosure.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The emulation guidance and TTP-to-skill mappings earn their place, but the body is padded with encyclopedic background Claude largely already knows (attribution consensus, sector lists, full campaign histories with time-sensitive dates and version numbers like 'Orion 2019.4-2020.2.1' and '~18,000 organizations'), placing it at 'mostly efficient but could be tightened' rather than lean level 3. | 2 / 3 |
Actionability | The emulation section gives specific direction (e.g. 'Use the c2/sliver skill... HTTPS beacons with long jitter, asymmetric encryption, optional domain-fronting'), but it points to other skills instead of providing executable commands or copy-paste-ready examples, fitting 'some concrete guidance but incomplete; missing key details.' | 2 / 3 |
Workflow Clarity | Phases are sequenced in kill-chain order (Initial Access through Exfil) and include a verification note ('verify the blue cell detects the new app, consent grant, and federation change') plus a detection checklist, but it reads as a tactic-indexed reference rather than a gated procedure and lacks explicit validate->fix->retry feedback loops, so it does not reach level 3. | 2 / 3 |
Progressive Disclosure | Sections are well-organized with clear headers, but the skill is a monolithic ~136-line single file with no external references, and reference-grade content (campaign histories, full malware/tooling catalog, complete TTP listing) is inline rather than split into one-level-deep reference files, matching the level-2 'content that should be separate is inline' anchor. | 2 / 3 |
Total | 8 / 12 Passed |