CtrlK
BlogDocsLog inGet started
Tessl Logo

active-directory-attacks

Provide comprehensive techniques for attacking Microsoft Active Directory environments. Covers reconnaissance, credential harvesting, Kerberos attacks, lateral movement, privilege escalation, and domain dominance for red team operations and penetration testing.

62

Quality

74%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/antigravity-active-directory-attacks/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a highly actionable, well-structured command reference with clean progressive disclosure into a single verified reference file. Its main weaknesses are redundant filler sections (duplicated Purpose/tool lists, vacuous 'When to Use') and non-systematic per-step validation in the multi-step workflows.

Suggestions

Remove the vacuous 'When to Use' section ('This skill is applicable to execute the workflow or actions described in the overview') and the Purpose section that duplicates the frontmatter description verbatim.

Consolidate the tool lists: the Prerequisites tool list and the Essential Tools table repeat the same tools — keep only the table (or the list) with the purpose column.

Add explicit validation checkpoints to the worked examples (e.g., verify the cracked service-account credentials with a low-impact command before psexec, and confirm ticket validity with klist before pass-the-ticket).

DimensionReasoningScore

Conciseness

The bulk is a lean command reference, but there is noticeable redundancy: the Purpose section repeats the description verbatim, the Essential Tools table duplicates the tool list from Prerequisites, the Quick Reference table re-states commands already shown, and 'When to Use' is vacuous filler. Matches 'mostly efficient but could be tightened'; not 2 because the core content is unpadded.

3 / 5

Actionability

Fully executable, copy-paste-ready commands throughout — exact Impacket/Rubeus/Mimikatz invocations, hashcat modes (-m 13100, -m 18200), and complete worked examples with placeholders covering the common cases. Matches anchor 5; not 4 because there are no significant gaps in executability.

5 / 5

Workflow Clarity

Clear sequenced workflow (clock sync → BloodHound recon → PowerView enumeration) with pre-operation checks (SMB-signing check before relay, zerologon check before exploit, patch-level verification), a post-exploit restore step, and a Troubleshooting table. Not 5 because validation/feedback loops are not systematic — e.g., Example 1 proceeds through cracking and psexec without verifying each step's outcome.

4 / 5

Progressive Disclosure

Well-organized sections with advanced material split into a single, real, one-level-deep reference (references/advanced-attacks.md, verified to exist with no nested references) that is explicitly signaled with an enumerated topic list ('delegation attacks, GPO abuse, RODC attacks, SCCM/WSUS...'). Matches anchor 5 for clear overview with well-signaled one-level-deep references.

5 / 5

Total

17

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description clearly communicates a well-scoped offensive AD capability with strong specificity and low conflict risk, but it omits any 'Use when...' trigger clause and lacks common synonyms/abbreviations like 'AD' or 'pentest'. Adding explicit trigger guidance would substantially improve it.

Suggestions

Append a trigger clause such as 'Use when performing authorized penetration tests or red team engagements against Active Directory / AD domains, or when the user mentions Kerberos, domain controllers, or domain dominance.'

Include common user-facing synonyms and abbreviations ('AD', 'pentest', 'domain controller') to improve natural trigger matching.

Name one or two signature techniques (e.g., Kerberoasting, DCSync, pass-the-hash) to sharpen the specificity from categories to concrete actions.

DimensionReasoningScore

Specificity

Lists six concrete coverage areas ('reconnaissance, credential harvesting, Kerberos attacks, lateral movement, privilege escalation, and domain dominance') with only minor gaps. Not 5 because these are attack categories rather than named concrete techniques (e.g., Kerberoasting, DCSync); clearly above 3's '1-2 concrete actions'.

4 / 5

Completeness

The 'what' is clear and concrete (comprehensive AD attack techniques across named areas), but there is no 'Use when...' clause or equivalent explicit trigger guidance, which caps completeness at 3 per the rubric guidelines. Not 4 because 'when' is entirely absent rather than merely imprecise.

3 / 5

Trigger Term Quality

Good natural keyword coverage ('Active Directory', 'red team', 'penetration testing', 'Kerberos') but misses common variations users actually say such as 'AD', 'pentest', or 'domain controller'. Not 5 because synonyms/abbreviations are missing; above 3 because most natural terms are present.

4 / 5

Distinctiveness Conflict Risk

Clear niche (Microsoft Active Directory offense) explicitly scoped by 'red team operations and penetration testing', giving minimal overlap risk with defensive or general skills. Matches anchor 5; not 4 because the triggers are genuinely distinct from neighboring skills.

5 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
boisenoise/skills-collections
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.