Content
65%Weight 40%Scale 1-3Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
A rich, well-organized adversary-emulation reference with concrete, tool-mapped emulation guidance and detection coverage, but it is a verbose monolithic document with no progressive disclosure and no explicit validation feedback loops for its destructive/risky operations.
Suggestions
Split the long TTP-by-tactic catalog, tooling table, campaign history, and detection sections into separate reference files (e.g., ttps.md, tooling.md, detection.md) referenced one level deep from SKILL.md, keeping the overview and emulation guidance inline.
Add an explicit validate→fix→retry checkpoint loop to the emulation guidance for destructive/risky operations (e.g., verify rootkit deployment in the isolated lab before chaining C2, and re-validate after each phase).
Tighten the campaign narratives and attribution/motivation prose to bare intelligence facts to reduce token weight without losing the actionable signal.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body avoids explaining concepts Claude already knows and the structured intelligence is the genuine content value, but the campaign narratives and attribution/motivation prose are discursive and could be tightened; at ~275 lines it is accurate yet padded relative to a lean reference. | 2 / 3 |
Actionability | The 'Emulation guidance' section maps each signature play to specific ATT&CK IDs, named malware patterns, and concrete tools (Sliver, the c2/phishing/payload-builder skills) with precise artifacts like '.jpg.bfe' double extensions, 'w32time.dll', and BPF magic-packet activation — concrete, specific, actionable guidance rather than vague direction. | 3 / 3 |
Workflow Clarity | Emulation steps are sequenced by kill-chain phase, but the operations are destructive/high-risk (kernel rootkits, domain takeover) and the body provides no explicit validate→fix→retry checkpoint loop, so workflow clarity is capped at 2 per the rubric's destructive-operations guideline. | 2 / 3 |
Progressive Disclosure | Content is well-sectioned with clear headers, but it is a single monolithic ~275-line SKILL.md with no bundle files and no one-level-deep references; the campaigns, TTP catalog, tooling table, emulation guidance, and detection sections are all inline and could be split into separate reference files. | 2 / 3 |
Total | 9 / 12 Passed |