Content
65%Weight 40%Scale 1-3Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is well-organized and highly actionable in its emulation guidance, but it is a monolithic document with no progressive disclosure and lacks validation checkpoints around its destructive-operation workflow.
Suggestions
Add explicit validation/verification checkpoints to the wiper and destructive-operation workflow (e.g., confirm isolation/scope before each destructive step, verify lab containment) to lift workflow clarity above 2.
Move the detailed campaign narratives, the full ATT&CK TTP catalog, and the signature-tooling table into separate reference files (e.g., CAMPAIGNS.md, TTPS.md, TOOLING.md) referenced one level deep from SKILL.md to improve progressive disclosure.
Trim the background-heavy attribution/targeting/campaign prose to only what is needed to inform emulation, reducing token cost.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The actionable core (TTPs, tooling table, emulation guidance) is efficient, but lengthy 'Attribution & motivation', 'Targeting', and 'Notable campaigns' narrative sections repeat threat-intel background that could be trimmed; it is mostly efficient with some padding. | 2 / 3 |
Actionability | The 'Emulation guidance (Decepticon)' section gives concrete, specific direction — exact tools (ASPXSpy variant, Plink renamed 'systems.exe', Mimikatz), exact staging paths ('C:\windows\temp\s\'), ATT&CK IDs, and a numbered 5-step wiper chain — which is actionable guidance for an instruction-only skill. | 3 / 3 |
Workflow Clarity | The emulation phases are sequenced (initial access → impact → hack-and-leak) with a numbered wiper chain, but there are no explicit validation/verification checkpoints or fix-retry feedback loops; per the rubric, destructive operations without validation cap workflow clarity at 2. | 2 / 3 |
Progressive Disclosure | Content is organized into clear sections, but it is a single monolithic ~170-line SKILL.md with no references/, scripts/, or assets/ files; detailed campaign histories, the full TTP catalog, and the tooling table are inline content that could be split into one-level-deep reference files. | 2 / 3 |
Total | 9 / 12 Passed |