Content
96%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
An exemplary orchestration-style skill body: dense, operational, and safe. The kill chain is explicitly sequenced with concrete sub-skill routing, the destructive operations are fenced with explicit authorization, rollback, canary-only, and abort gates, and the only weakness is minor — unverifiable external reference paths and slightly cramped table cells.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The ~90-line body is lean and operational: a copy-paste ThreatProfile seed, a compact phase table, a CONOPS list, and terse safety gates. It assumes Claude's competence (no explanation of MITRE, DCSync, or Kerberoast) and every section carries engagement-specific value — anchor 5, not 4, since nothing trimmable stands out. | 5 / 5 |
Actionability | Guidance is fully concrete: a copy-paste-ready 'plan/threat-profile.json' JSON block, an explicit 'copy into conops.json' list, per-phase executing-agent and skill routing with specific paths, and named artifacts (deconfliction.json, cleanup.json). As an instruction-only skill its guidance is executable throughout — anchor 5. | 5 / 5 |
Workflow Clarity | The kill chain is a numbered 11-phase table with MITRE mappings plus a grouped CONOPS sequence, and the destructive operations (EDR tampering, ransomware impact) have explicit validation gates: authorization, lure-deconfliction, lab/canary host first, 'confirm rollback', canary-only impact, an EMERGENCY abort criterion, and a deconfliction checklist. Validation is present (no cap at 3) and the gates plus abort loop match anchor 5; it exceeds anchor 4 because checkpoints are explicit rather than implicit. | 5 / 5 |
Progressive Disclosure | The body is a well-sectioned overview that routes detail outward: '../../references/apt-groups.md' is clearly signaled and one level deep, and each phase names its executing skill. However the skill ships no bundle of its own, so the referenced paths cannot be verified, and a few table cells cram two skill paths into one cell — good structure with minor organization gaps, anchor 4 rather than 5. | 4 / 5 |
Total | 19 / 20 Passed |