Content
78%Weight 40%Scale 1-5Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is a highly actionable, well-structured command reference with clean progressive disclosure into a single verified reference file. Its main weaknesses are redundant filler sections (duplicated Purpose/tool lists, vacuous 'When to Use') and non-systematic per-step validation in the multi-step workflows.
Suggestions
Remove the vacuous 'When to Use' section ('This skill is applicable to execute the workflow or actions described in the overview') and the Purpose section that duplicates the frontmatter description verbatim.
Consolidate the tool lists: the Prerequisites tool list and the Essential Tools table repeat the same tools — keep only the table (or the list) with the purpose column.
Add explicit validation checkpoints to the worked examples (e.g., verify the cracked service-account credentials with a low-impact command before psexec, and confirm ticket validity with klist before pass-the-ticket).
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The bulk is a lean command reference, but there is noticeable redundancy: the Purpose section repeats the description verbatim, the Essential Tools table duplicates the tool list from Prerequisites, the Quick Reference table re-states commands already shown, and 'When to Use' is vacuous filler. Matches 'mostly efficient but could be tightened'; not 2 because the core content is unpadded. | 3 / 5 |
Actionability | Fully executable, copy-paste-ready commands throughout — exact Impacket/Rubeus/Mimikatz invocations, hashcat modes (-m 13100, -m 18200), and complete worked examples with placeholders covering the common cases. Matches anchor 5; not 4 because there are no significant gaps in executability. | 5 / 5 |
Workflow Clarity | Clear sequenced workflow (clock sync → BloodHound recon → PowerView enumeration) with pre-operation checks (SMB-signing check before relay, zerologon check before exploit, patch-level verification), a post-exploit restore step, and a Troubleshooting table. Not 5 because validation/feedback loops are not systematic — e.g., Example 1 proceeds through cracking and psexec without verifying each step's outcome. | 4 / 5 |
Progressive Disclosure | Well-organized sections with advanced material split into a single, real, one-level-deep reference (references/advanced-attacks.md, verified to exist with no nested references) that is explicitly signaled with an enumerated topic list ('delegation attacks, GPO abuse, RODC attacks, SCCM/WSUS...'). Matches anchor 5 for clear overview with well-signaled one-level-deep references. | 5 / 5 |
Total | 17 / 20 Passed |