Content
57%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is information-dense and actionable with concrete emulation mappings and a strong safety preamble, but it reads as an inline reference monolith without a sequenced validation-bearing workflow or progressive file structure.
Suggestions
Add an explicit ordered emulation workflow with validation checkpoints (e.g. confirm scope/ROE → enumerate authorized targets → execute emulation step → verify artifact logged → teardown) so destructive-adjacent work clears the workflow-clarity cap.
Move the bulk TTP catalogue and detection rules into reference files (e.g. references/ttps.md, references/detection.md) and link to them from SKILL.md to improve progressive disclosure.
Trim the narrative attribution and campaign-history prose to the minimum needed for emulation context, keeping the token budget focused on actionable guidance.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Dense and assumes Claude's competence (no basic explanations of ATT&CK or password spraying), but narrative attribution/campaign prose ("FireEye/Mandiant assessed APT33 works at the behest...") pads the body with threat-intel context beyond what an emulation skill strictly needs. | 3 / 5 |
Actionability | Gives concrete, mostly executable guidance — "Stand up a Sliver HTTP listener", "low-and-slow spray...with a custom user-agent and lockout-aware throttling", specific ports 808/880, named tools — with only minor gaps where it defers to "Decepticon's X skill" without exact commands. | 4 / 5 |
Workflow Clarity | The emulation guidance is a set of capability mappings rather than a sequenced workflow, and despite a strong authorized-use safety blockquote and teardown/logging notes, it lacks explicit validate→fix→retry checkpoints, which caps destructive/batch-adjacent workflow clarity at 3. | 3 / 5 |
Progressive Disclosure | No bundle files exist, so all content (full TTP catalogue, detection guidance, campaign history) is inlined in a single SKILL.md; section headers give internal structure but content that could live in separate reference files is not split out. | 3 / 5 |
Total | 13 / 20 Passed |