CtrlK
BlogDocsLog inGet started
Tessl Logo

netexec

NetExec (CrackMapExec successor) — unified SMB/LDAP/MSSQL/WinRM/RDP/SSH/FTP/VNC protocol auth + post-auth modules. 200+ modules incl. BloodHound auto-ingest, ESC1-15 scanning, PrintNightmare, LDAP relay.

61

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/ad/netexec/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, token-efficient command playbook that assumes competence and covers the common NetExec workflows with copy-paste examples. Its main weakness is the absence of explicit validation/feedback checkpoints around destructive batch operations (spray, DCsync, NTDS dump), which the rubric caps at 3 for workflow clarity.

Suggestions

Add explicit validation checkpoints before destructive/batch steps, e.g. 'Confirm creds valid on one host before spraying the subnet' and 'Check lockout policy before password spray', to lift workflow clarity above the destructive-skill cap of 3.

Move the full module catalog (section 3.8) and the Decepticon wrapper skeleton into referenced files (e.g. references/modules.md, scripts/netexec_wrapper.py) to improve progressive disclosure toward a 5.

Trim the marketing line ('Swiss-army knife of Windows / AD pentest') and the unverified 'Known exemplars' statistics to push conciseness to a 5.

DimensionReasoningScore

Conciseness

Lean and command-driven, assuming Claude's domain competence with terse inline comments; only minor trimmable bits remain (the 'Swiss-army knife' marketing line and the 'Known exemplars' usage statistics).

4 / 5

Actionability

Almost entirely copy-paste-ready executable nxc/hashcat commands covering the common cases (sweep, BloodHound, ADCS, kerberoast, AS-REP, spider, dcsync, spray, modules, output formats); the Python wrapper is explicitly labeled a skeleton, justifying its partial form.

5 / 5

Workflow Clarity

Numbered sections provide a rough sequence, but batch/destructive operations (subnet cred sweeps, DCsync, NTDS dump, password spray) lack explicit validate-then-proceed feedback loops; the rubric caps workflow clarity at 3 for destructive/batch skills missing validation.

3 / 5

Progressive Disclosure

No bundle files exist, so the single well-organized file with clear numbered section headers and a one-level Cross-references block is appropriate; minor gaps (the module catalog and Decepticon integration could be split into referenced files) keep it just below a 5.

4 / 5

Total

16

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-scoped description that clearly conveys what NetExec does and is highly distinctive, but it omits any explicit 'when to use' trigger guidance and leans on capability nouns rather than verb-actions. Adding a 'Use when...' clause and the natural CLI synonyms (nxc, cme) would raise the weakest dimensions.

Suggestions

Append an explicit trigger clause, e.g. 'Use when running AD/Windows pentest cred sweeps, spraying, kerberoasting, or BloodHound/ADCS collection with nxc/cme.'

Include the natural CLI synonyms 'nxc' and 'cme' directly in the description text, not only in metadata, so users who type those commands trigger the skill.

Reframe a few capability nouns as verb-actions (e.g. 'sweeps credentials across SMB/LDAP/...', 'kerberoasts', 'dumps NTDS') to sharpen specificity.

DimensionReasoningScore

Specificity

Lists several concrete capabilities ('protocol auth + post-auth modules', 'BloodHound auto-ingest', 'ESC1-15 scanning', 'PrintNightmare', 'LDAP relay') but frames them as capability nouns/module names rather than crisp verb-actions, and '200+ modules' is a quantity claim rather than an action.

4 / 5

Completeness

The 'what' is clear and detailed, but there is no 'Use when...' clause or equivalent explicit trigger guidance; the rubric caps completeness at 3 in that case, matching the 'clear what, missing when' anchor.

3 / 5

Trigger Term Quality

Good coverage of protocols and tool names (NetExec, CrackMapExec, SMB, LDAP, BloodHound, PrintNightmare) but the natural CLI synonyms 'nxc'/'cme' and action terms 'spray/sweep/kerberoast' are absent from the description (they appear only in metadata).

4 / 5

Distinctiveness Conflict Risk

Names a highly specific tool (NetExec/CrackMapExec successor) plus eight protocols and named modules, occupying a clear AD/Windows-pentest niche with minimal conflict risk.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.