Content
50%Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is a thorough, well-structured threat-intel and emulation profile with concrete tool mappings and detection guidance, but it is prose-heavy and encyclopedic rather than lean, lacks executable code and validation checkpoints, and keeps all content inline.
Suggestions
Add executable commands or a concrete runbook (e.g., the exact Sliver listener/redirector setup and the marked-impact-file commands) instead of prose-only tool references to lift actionability.
Insert explicit validation/safety checkpoints in the emulation workflow — confirm scope, verify the impact marker is reversible, and confirm detections fired — especially around the destructive-operation steps.
Split the encyclopedic campaign and tooling reference into a separate references file so SKILL.md stays a lean overview that points one level deep.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is well-organized but dense; the intro and campaign entries restate widely known background (Sony, WannaCry, Bangladesh Bank) that Claude largely already knows, so it could be tightened despite being a threat-intel reference. | 2 / 3 |
Actionability | The 'Emulation guidance (Decepticon)' section maps TTPs to specific tools/skills (Sliver, defense-evasion, Responder) and the detection section names concrete indicators, but the guidance is prose with no executable code or copy-paste commands. | 2 / 3 |
Workflow Clarity | The emulation chain is sequenced (initial access -> C2 -> execution/persistence -> evasion -> credentials -> discovery -> exfil -> impact), but destructive operations lack explicit validate/verify/retry checkpoints, capping this dimension at 2 per the rubric. | 2 / 3 |
Progressive Disclosure | Everything is inline in one monolithic document with clear sections but no bundle files and no one-level-deep references, so content that could live in separate reference files is not split out. | 2 / 3 |
Total | 8 / 12 Passed |