Content
85%Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A well-structured, actionable adversary-emulation playbook with a concrete kill-chain table, copy-paste templates, and explicit safety gates. Its only weakness is mild verbosity where the intro and targeting sections overlap the description and table.
Suggestions
Trim the opening blockquote and 'When to emulate APT29' section — the description and kill-chain table already convey the targeting and tradecraft signature, so the restatement costs tokens without adding operational value.
Cut editorial asides ('APT29 is patient', 'that is the whole point of the OAuth tradecraft', 'not smash-and-grab') that restate motivation Claude can infer from the actor profile.
Consider moving the ThreatProfile seed JSON to a references/threat-profile.template.json to keep the overview lean, since it is a fill-in template rather than narrative.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is dense and operational, but the opening blockquote and 'When to emulate APT29' section restate targeting/tradecraft already conveyed by the description and kill-chain table, and editorial asides like 'APT29 is patient' and 'that is the whole point of the OAuth tradecraft' could be trimmed. | 2 / 3 |
Actionability | Provides copy-paste-ready guidance: a complete ThreatProfile JSON seed, a MITRE-mapped kill-chain table with exact executing-agent skill paths, and concrete rules (app naming 'redteam-<engagement-id>-*', spray cadence 'one attempt per account'). For an instruction-only skill the guidance is specific and actionable. | 3 / 3 |
Workflow Clarity | A clearly sequenced 5-phase kill-chain/CONOPS with explicit go/no-go safety gates ('require explicit, written cloud-tenant authorization'), an EMERGENCY abort trigger, deconfliction steps, and end-of-engagement cleanup serving as validation checkpoints for a high-blast-radius operation. | 3 / 3 |
Progressive Disclosure | Organized into clearly headed sections (ThreatProfile, Kill-chain, CONOPS, OPSEC, RoE, Deconfliction, Fidelity) with one-level-deep, clearly signaled cross-skill references — the table's 'Executing agent → skill' column and the '../../references/apt-groups.md' map — and no nested or monolithic walls of text. | 3 / 3 |
Total | 11 / 12 Passed |