Content
50%Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is a thorough, well-structured APT34 adversary-emulation reference with genuinely novel TTP/tooling detail and a clear kill-chain sequence. Its weaknesses are verbosity in narrative prose, emulation guidance that defers to other skills rather than giving executable steps, absent operational validation checkpoints, and a monolithic structure that underuses progressive disclosure.
Suggestions
Tighten the Attribution/Notable-campaigns prose into compact reference rows (date, vector, tooling, source) and drop narrative Claude could infer, to lift conciseness.
Add explicit operational validation checkpoints to the emulation sequence (e.g. 'verify in-scope authorization and access before each tactic', 'confirm beacon/DNS callback before proceeding to recon') to satisfy the destructive-workflow feedback-loop requirement.
Move the full TTP-by-tactic catalog, signature-tooling list, and detailed detection rules into references/ files (e.g. TTPS.md, TOOLING.md, DETECTION.md) and keep SKILL.md as a concise overview that links one level deep, improving progressive disclosure.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Much of the threat-intel detail (specific campaign dates, software S-IDs, exact TTP mappings) is genuinely novel reference content that earns its place, but the attribution narrative ('It conducts long-running, reconnaissance-heavy intrusions...') and campaign prose are explanatory padding that could be tightened. It is mostly efficient but not 'every token earns its place', sitting below the lean anchor and above the verbose 'explains concepts Claude knows' anchor. | 2 / 3 |
Actionability | Concrete specifics exist — the LOLBin recon sequence ('whoami', 'net user'/'net group', 'ipconfig /all', 'netstat -an', 'net accounts', 'sc query'), 'certutil -decode', and registry paths like 'HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Notification Packages' — but the emulation guidance largely defers to other skills ('use the phishing skill to craft...', 'Configure your C2/Sliver profile...') rather than giving complete, copy-paste-ready executable content. As an instruction-only skill it is actionable yet incomplete, matching the 'some concrete guidance but incomplete' anchor. | 2 / 3 |
Workflow Clarity | A clear kill-chain sequence is stated ('phish → execute loader → DNS/HTTP C2 → recon → credential harvest → escalate → lateral to DC → stage → exfil via mail/DNS') and the body is organized by tactic, but there are no explicit validate→fix→retry checkpoints for the destructive/risky red-team operations. Per the rubric, missing validation/feedback loops in destructive-operation workflows caps workflow clarity at 2 rather than 3. | 2 / 3 |
Progressive Disclosure | The body is well-organized into clear sections (Attribution, Targeting, Notable campaigns, TTPs by tactic, Tooling, Emulation guidance, Detection, Sources), but it is a single 150+ line monolithic file with no bundle references; the full TTP catalog, campaign history, and detection rules are inline content that could be split into separate reference files. This matches 'some structure but content that should be separate is inline' rather than the well-signaled one-level-deep reference pattern of the top anchor. | 2 / 3 |
Total | 8 / 12 Passed |