Content
61%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is a well-structured, actionable adversary-emulation profile rich in specific IOCs and TTPs, but it repeats techniques across sections and lacks explicit validation checkpoints in its emulation workflow. Splitting deep reference material into bundle files and adding verification steps would raise the weaker dimensions.
Suggestions
Add explicit validation/verification checkpoints to the emulation guidance (e.g., 'Confirm target is in scope and ROE before deploying', 'Verify the side-loaded DLL executes only within the scoped host', 'Confirm implant is decommissionable after the engagement') to lift workflow clarity above the cap.
De-duplicate techniques that recur across the 'TTPs by tactic', 'Emulation guidance', and 'Detection & defense' sections — keep each section's lens distinct or cross-reference instead of restating.
Move the detailed campaign history and/or the full TTP/tooling tables into a references/ bundle file (e.g., CAMPAIGNS.md, TTPO_MATRIX.md) with one-level-deep links from SKILL.md to improve progressive disclosure.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | Most content is genuinely novel threat intelligence Claude would not already know, but the same techniques (e.g., CVE-2017-11882, DLL side-loading, mshta chains) are restated across the 'TTPs by tactic', 'Emulation guidance', and 'Detection & defense' sections, adding padding that could be tightened. | 3 / 5 |
Actionability | The emulation and detection sections give concrete guidance with specific process names (rekeywiz.exe, mshta.exe, mstsc.exe), CVE numbers, registry paths, and WMI queries, with only minor gaps from relying on referenced sibling skills (phishing, payload-builder). | 4 / 5 |
Workflow Clarity | The emulation guidance is roughly sequenced (initial access → execution → evasion → … → exfiltration) with an authorized-use caveat, but there are no validation/verification checkpoints for a destructive emulation workflow, so per the rubric cap workflow clarity cannot exceed 3. | 3 / 5 |
Progressive Disclosure | The body is well organized with clear section headers and no nested references, and as a single coherent adversary profile a one-file layout is defensible; however it is a ~145-line monolith with no bundle files that could offload campaign history or detailed TTP tables into references. | 4 / 5 |
Total | 14 / 20 Passed |