Content
65%Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A thorough, well-organized adversary-emulation profile with genuinely actionable emulation and detection guidance mapped to ATT&CK. It loses points for missing validation/feedback loops in the workflow and for keeping dense reference material inline rather than splitting it into progressive-disclosure reference files.
Suggestions
Add explicit validation/verification checkpoints to the emulation workflow (e.g., confirm scope authorization and log every artifact before advancing to the next kill-chain phase), especially given the destructive/wiper context.
Move the detailed TTP catalog, campaign history, and signature-tooling reference into a separate references/ file (e.g., TTPS.md) and keep SKILL.md as a concise overview that links out one level deep.
Tighten the attribution/targeting/campaign narrative prose to reduce token weight without losing the specific vendor citations and dates.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is mostly efficient threat-intel reference (campaign dates, S-numbers, CVEs, vendor citations) that Claude would not reliably know and does not pad with basic concept explanations, but the attribution/targeting/campaign narrative prose is dense and could be tightened. | 2 / 3 |
Actionability | Emulation guidance maps each APT33 TTP chain to concrete Decepticon actions ('stand up a Sliver HTTP listener', 'enable symmetric-crypto transport', 'front C2 through an authorized Azure App Service'), and the detection section gives specific alert/policy actions; as an instruction-only skill with actionable, specific guidance, absence of literal code is not penalized. | 3 / 3 |
Workflow Clarity | Emulation steps are organized in kill-chain order (initial access through persistence), but there are no explicit validation checkpoints or validate-fix-retry feedback loops, and the destructive/wiper context means the missing verification step caps this at 2. | 2 / 3 |
Progressive Disclosure | The body is well-sectioned but no bundle files exist, and the lengthy reference material (full TTP catalog, campaign list, tooling with S-numbers) is kept inline rather than externalized into one-level-deep reference files. | 2 / 3 |
Total | 9 / 12 Passed |