Content
57%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A practical, actionable operator skill with good code/config examples and a useful comparison table, but it is somewhat verbose with tutorial-style concept explanations, lacks validation checkpoints around destructive operations, and does not split detailed material into bundle reference files.
Suggestions
Trim explanatory prose about EDR hooking, static-string hashing, and module stomping to the operational essentials — Claude already understands these concepts.
Add explicit validation/verification checkpoints around destructive workflows (e.g., confirm listener is reachable before building a payload, verify payload executes before lateral movement).
Move the OPSEC technique deep-dive and the full command reference into separate files under references/ and link to them from SKILL.md to improve progressive disclosure.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Mostly efficient with dense, useful tables and config/command examples, but several sections explain concepts Claude largely already knows ('Most EDRs hook NtAllocateVirtualMemory...', 'strings demon.exe | grep -i shell returns nothing', module stomping primer) that could be trimmed. | 3 / 5 |
Actionability | Provides copy-paste-ready build commands, a full HCL profile example, numbered client-UI build steps, and a concrete command cheatsheet; minor gaps only (the CLI build path is explicitly noted as unavailable, forcing the Qt UI). | 4 / 5 |
Workflow Clarity | A clear sequence (Setup → Configure profile → Build Demon → Run commands) is present, but destructive/batch operations (payload generation, lateral movement via jump, mimikatz) have no validation or verification checkpoints, capping this dimension at 3 per the rubric. | 3 / 5 |
Progressive Disclosure | Well-organized section headers, but the skill is a single long file with no bundle files in references/scripts/assets; content like the OPSEC deep-dive, command reference, and comparison table that could live in one-level-deep reference files is inlined. | 3 / 5 |
Total | 13 / 20 Passed |