Content
90%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A dense, high-quality playbook body: copy-paste threat-profile seed, fully mapped kill chain with executable hand-offs, actor-accurate OPSEC fidelity rules, and well-considered safety gates for edge-device and OT risks. The only gaps are the absence of an explicit error-recovery loop in the workflow and cross-references that point outside the skill's own bundle.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Lean and efficient throughout — every section carries actor-specific information (ThreatProfile seed, kill-chain table with MITRE mappings, CONOPS, OPSEC fidelity rules, RoE gates, deconfliction, deviation notes) with zero padding or explanation of concepts Claude already knows. No time-sensitive content outside a properly framed topical CISA reference. | 5 / 5 |
Actionability | Fully actionable: a copy-paste-ready ThreatProfile JSON block, an 8-row kill-chain table mapping each phase to concrete actions, MITRE techniques, and exact executing-skill paths, named LOLBins (netsh, wmic, ntdsutil, vssadmin), and explicit CONOPS steps. For an instruction-only planning skill, the guidance is specific and executable as written. | 5 / 5 |
Workflow Clarity | A clear 8-phase kill chain with a sequenced 5-step CONOPS and explicit safety checkpoints — 'require device-write authorization and confirm a config backup exists before exploiting', an EMERGENCY abort trigger, and the IT/OT boundary gate appropriately cap the destructive edge-exploitation risk. Not 5 because there is no error-recovery feedback loop (e.g., what to do if the edge exploit fails or the device becomes unresponsive) once execution hands off to the linked skills. | 4 / 5 |
Progressive Disclosure | Good structure for a playbook overview: well-organized sections, all detail delegated to one-level-deep, per-phase skill paths in the kill-chain table, and the single reference to `../../references/apt-groups.md` clearly signaled ('see the industry → actor map'). Not 5 because the apt-groups.md reference sits outside this skill's bundle (no bundle references/, scripts/, or assets/ exist), so the navigation target cannot be verified from the skill itself, and the many cross-skill paths are unverifiable from this SKILL.md. | 4 / 5 |
Total | 18 / 20 Passed |