Content
93%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A dense, well-structured adversary-emulation playbook that is fully actionable as an orchestrator: complete threat-profile seed, unambiguous kill-chain routing with MITRE mapping, and unusually strong safety/RoE gates with verbatim abort criteria. The only notable gap is the absence of an explicit pre-flight verification checkpoint for the destructive on-chain phases, leaving workflow clarity just short of the top anchor.
Suggestions
Add an explicit pre-flight validation step to the kill-chain or CONOPS: e.g. 'Before phases 7–9, verify the configured RPC URL is the testnet/Anvil fork endpoint recorded in deconfliction.json — abort if it resolves to a mainnet RPC.'
Turn the RoE safety gates into a short copy-paste checklist (fork RPC verified → canary wallets funded → persona marked → lure deconflicted) so the gates function as sequenced checkpoints rather than prose rules.
In the CONOPS kill_chain, annotate steps 3–4 (on-chain phases) with their testnet/fork precondition inline, so the constraint is visible at the point of execution rather than only in the RoE section.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The ~93-line body packs threat-profile seed, an 11-phase kill-chain routing table, CONOPS, OPSEC, RoE gates, deconfliction, and fidelity notes with zero filler — it never explains concepts Claude already knows (what a DLL side-load or a DeFi bridge is) and assumes competence throughout. Every section maps to a concrete planning artifact, matching the level-5 anchor ('lean and efficient; every token earns its place'); level 4 would require trimmable over-explanation, and none is evident. | 5 / 5 |
Actionability | Guidance is copy-paste ready: the complete `plan/threat-profile.json` seed JSON, exact routing paths per phase (e.g. `/skills/standard/contracts/bridge-exploit/SKILL.md`), a numbered CONOPS to copy into `conops.json`, and verbatim EMERGENCY-abort language. Per the rubric's instruction-only-skill note, absence of code is not penalized when guidance is actionable — and this is fully actionable with specific named artifacts (`deconfliction.json`, `cleanup.json`). It exceeds level 4 ('minor gaps'): execution detail is deliberately and correctly delegated to the routed sub-skills. | 5 / 5 |
Workflow Clarity | The 11-phase sequence is clearly numbered, mapped to MITRE techniques and CONOPS stages, and includes explicit safety checkpoints (MUST-run-on-fork rule, verbatim `EMERGENCY` abort criterion, lure deconfliction requirement). However, for inherently destructive on-chain operations (phases 7–11) there is no explicit pre-flight validation step in the sequence itself — e.g. 'verify the RPC endpoint is an Anvil fork/testnet before executing phases 7–9' — so the level-5 anchor's 'explicit validation steps' is not fully met; this fits level 4 ('clear sequence with most checkpoints present; minor validation gaps') better than level 5. | 4 / 5 |
Progressive Disclosure | The SKILL.md is itself an overview that routes all execution detail to one-level-deep, clearly signaled sub-skill paths (dedicated routing column in the kill-chain table, plus inline links like `(see ../../references/apt-groups.md)` and the lure-deconfliction path in RoE). No content that belongs in a separate file is inlined; the structure matches the level-5 anchor (clear overview with well-signaled one-level-deep references, easy navigation), which is why it sits above level 4 rather than merely at it. | 5 / 5 |
Total | 19 / 20 Passed |