Content
65%Weight 40%Scale 1-3Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is a thorough, highly actionable adversary-emulation profile with concrete emulation and detection guidance, but it is a monolithic inline document lacking validation checkpoints in its workflows and any reference-file structure. Splitting the campaign/TTP/tooling catalogs into reference files and adding verify steps for destructive operations would improve it.
Suggestions
Move the campaign timeline, full ATT&CK TTP catalog, and tooling table into one-level-deep reference files (e.g. references/campaigns.md, references/ttps.md) and keep SKILL.md as an overview with signaled links.
Add explicit validation/checkpoint steps for destructive or lab-only operations (USB worm, kernel-driver deployment), e.g. verify isolation and scope before executing, and confirm cleanup afterward.
Trim redundant alias repetitions and prose in the body to tighten token use without losing the reference value.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is dense reference material (campaigns, malware families, ATT&CK mappings) that Claude does not already know, so most tokens earn their place, but the volume is large and could be tightened or offloaded to reference files rather than held inline. | 2 / 3 |
Actionability | The 'Emulation guidance' and 'Detection & defense' sections give concrete, executable guidance — specific technique chains, signed-EXE/DLL/payload triads, registry keys, and commands like `code.exe tunnel`, `rar.exe a -hp`, `vssadmin create shadow` — well beyond abstract description. | 3 / 3 |
Workflow Clarity | Content is logically sequenced by ATT&CK tactic and phase, but there are no explicit validation checkpoints or feedback loops, and the destructive USB-worm / kernel-driver operations only carry an authorized-use caveat rather than verify steps, which caps the score at 2. | 2 / 3 |
Progressive Disclosure | Sections are well-organized, but no references/scripts/assets bundle exists and the entire profile — campaigns, TTP catalog, tooling table, detections — lives inline in one large SKILL.md, so content that should be split across one-level-deep reference files is kept inline. | 2 / 3 |
Total | 9 / 12 Passed |